2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3828 | MEDIUM | 6.1 | 0.3% | Jul 22, 2023 | A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0. It has been classified as problematic.... |
| CVE-2023-3827 | MEDIUM | 6.1 | 0.3% | Jul 22, 2023 | A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0 and classified as problematic. Affected... |
| CVE-2023-3247 | MEDIUM | 4.3 | 0.7% | Jul 22, 2023 | In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP Digest Authentication,... |
| CVE-2023-28530 | MEDIUM | 5.4 | 0.5% | Jul 22, 2023 | IBM Cognos Analytics 11.1 and 11.2 is vulnerable to stored cross-site scripting, caused by improper validation of SVG Fi... |
| CVE-2023-25929 | MEDIUM | 5.4 | 0.4% | Jul 22, 2023 | IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2023-3603 | MEDIUM | 6.5 | 0.8% | Jul 21, 2023 | A missing allocation check in sftp server processing read requests may cause a NULL dereference on low-memory conditions... |
| CVE-2023-37905 | MEDIUM | 6.1 | 0.5% | Jul 21, 2023 | ckeditor-wordcount-plugin is an open source WordCount Plugin for CKEditor. It has been discovered that the `ckeditor-wor... |
| CVE-2023-37901 | MEDIUM | 5.4 | 0.4% | Jul 21, 2023 | Indico is an open source a general-purpose, web based event management tool. There is a Cross-Site-Scripting vulnerabili... |
| CVE-2023-25841 | MEDIUM | 6.1 | 0.5% | Jul 21, 2023 | There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux ... |
| CVE-2023-38187 | MEDIUM | 6.5 | 0.7% | Jul 21, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2023-38173 | MEDIUM | 4.3 | 0.6% | Jul 21, 2023 | Microsoft Edge for Android Spoofing Vulnerability |
| CVE-2023-35392 | MEDIUM | 4.7 | 0.7% | Jul 21, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2023-3102 | MEDIUM | 5.3 | 0.5% | Jul 21, 2023 | A sensitive information leak issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.... |
| CVE-2023-37742 | MEDIUM | 6.1 | 0.4% | Jul 21, 2023 | WebBoss.io CMS before v3.7.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability. |
| CVE-2023-3822 | MEDIUM | 6.1 | 0.5% | Jul 21, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4. |
| CVE-2023-3821 | MEDIUM | 5.4 | 0.5% | Jul 21, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.6.4. |
| CVE-2023-3819 | MEDIUM | 6.5 | 0.6% | Jul 21, 2023 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4. |
| CVE-2023-3484 | MEDIUM | 6.5 | 0.5% | Jul 21, 2023 | An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starti... |
| CVE-2023-32478 | MEDIUM | 4.9 | 0.4% | Jul 21, 2023 | Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A ... |
| CVE-2023-3815 | MEDIUM | 6.1 | 0.5% | Jul 21, 2023 | A vulnerability, which was classified as problematic, has been found in y_project RuoYi up to 4.7.7. Affected by this is... |
| CVE-2023-25836 | MEDIUM | 5.4 | 0.4% | Jul 21, 2023 | There is a Cross-site Scripting vulnerability in Esri Portal for ArcGIS Sites in versions 10.9 and below that may allow ... |
| CVE-2023-32625 | MEDIUM | 4.3 | 0.3% | Jul 21, 2023 | Cross-site request forgery (CSRF) vulnerability in TS Webfonts for SAKURA 3.1.2 and earlier allows a remote unauthentica... |
| CVE-2023-32624 | MEDIUM | 6.1 | 0.5% | Jul 21, 2023 | Cross-site scripting vulnerability in TS Webfonts for SAKURA 3.1.0 and earlier allows a remote unauthenticated attacker ... |
| CVE-2023-3800 | MEDIUM | 6.6 | 0.6% | Jul 20, 2023 | A vulnerability was found in EasyAdmin8 2.0.2.2. It has been classified as problematic. Affected is an unknown function ... |
| CVE-2023-37645 | MEDIUM | 5.3 | 23.8% | Jul 20, 2023 | eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/re... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now