2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49169 | MEDIUM | 5.4 | 0.4% | Dec 15, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in datafeedr.Com Ads ... |
| CVE-2023-50871 | MEDIUM | 4.3 | 0.4% | Dec 15, 2023 | In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed |
| CVE-2023-50870 | HIGH | 8.8 | 0.3% | Dec 15, 2023 | In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible |
| CVE-2023-49165 | MEDIUM | 5.4 | 0.4% | Dec 15, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Real Big Plugins C... |
| CVE-2023-49160 | MEDIUM | 5.4 | 0.4% | Dec 15, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in formzu Inc. Formzu... |
| CVE-2023-48765 | MEDIUM | 5.4 | 0.4% | Dec 15, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Till Krüss Email A... |
| CVE-2023-46116 | HIGH | 8.8 | 1.3% | Dec 15, 2023 | Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applicati... |
| CVE-2023-49898 | HIGH | 7.2 | 2.3% | Dec 15, 2023 | In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on t... |
| CVE-2023-30867 | MEDIUM | 4.9 | 0.9% | Dec 15, 2023 | In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fu... |
| CVE-2023-33222 | CRITICAL | 9.8 | 1.3% | Dec 15, 2023 | When handling contactless cards, usage of a specific function to get additional information from the card which... |
| CVE-2023-33221 | CRITICAL | 9.8 | 1.0% | Dec 15, 2023 | When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying... |
| CVE-2023-33220 | CRITICAL | 9.8 | 1.1% | Dec 15, 2023 | During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some att... |
| CVE-2023-33219 | CRITICAL | 9.8 | 1.1% | Dec 15, 2023 | The handler of the retrofit validation command doesn't properly check the boundaries when performing certain valida... |
| CVE-2023-33218 | CRITICAL | 9.8 | 1.1% | Dec 15, 2023 | The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow. This cou... |
| CVE-2023-6839 | MEDIUM | 5.3 | 0.5% | Dec 15, 2023 | Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specifi... |
| CVE-2023-6553 | CRITICAL | 9.8 | 97.8% | Dec 15, 2023 | The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1... |
| CVE-2023-48624 | MEDIUM | 5.4 | 0.6% | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2023-48623 | MEDIUM | 5.4 | 0.6% | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2023-48622 | MEDIUM | 5.4 | 0.6% | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2023-48621 | MEDIUM | 5.4 | 0.6% | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2023-48620 | MEDIUM | 5.4 | 0.6% | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2023-48619 | MEDIUM | 5.4 | 0.6% | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2023-48618 | MEDIUM | 5.4 | 0.6% | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerabilit... |
| CVE-2023-48617 | MEDIUM | 5.4 | 0.6% | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerabilit... |
| CVE-2023-48616 | MEDIUM | 5.4 | 0.6% | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now