2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48440 | MEDIUM | 5.4 | 0.6% | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2023-47065 | MEDIUM | 5.4 | 0.6% | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerabilit... |
| CVE-2023-47064 | MEDIUM | 5.4 | 0.6% | Dec 15, 2023 | Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2023-33217 | HIGH | 7.5 | 0.7% | Dec 15, 2023 | By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent ... |
| CVE-2023-6838 | MEDIUM | 6.1 | 0.4% | Dec 15, 2023 | Reflected XSS vulnerability can be exploited by tampering a request parameter in Authentication Endpoint. This can be pe... |
| CVE-2023-6837 | HIGH | 8.2 | 0.5% | Dec 15, 2023 | Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order... |
| CVE-2023-6836 | HIGH | 7.5 | 0.5% | Dec 15, 2023 | Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely ava... |
| CVE-2023-6835 | MEDIUM | 5.3 | 0.5% | Dec 15, 2023 | Multiple WSO2 products have been identified as vulnerable due to lack of server-side input validation in the Forum featu... |
| CVE-2023-48395 | MEDIUM | 6.5 | 0.7% | Dec 15, 2023 | Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special f... |
| CVE-2023-48394 | HIGH | 8.8 | 0.9% | Dec 15, 2023 | Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file wit... |
| CVE-2023-48393 | MEDIUM | 4.3 | 0.6% | Dec 15, 2023 | Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial... |
| CVE-2023-48392 | CRITICAL | 9.8 | 0.6% | Dec 15, 2023 | Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An un... |
| CVE-2023-48390 | CRITICAL | 9.8 | 1.1% | Dec 15, 2023 | Multisuns EasyLog web+ has a code injection vulnerability. An unauthenticated remote attacker can exploit this vulnerabi... |
| CVE-2023-48389 | HIGH | 7.5 | 1.3% | Dec 15, 2023 | Multisuns EasyLog web+ has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated rem... |
| CVE-2023-48388 | CRITICAL | 9.8 | 0.9% | Dec 15, 2023 | Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerab... |
| CVE-2023-48387 | HIGH | 8.8 | 1.0% | Dec 15, 2023 | TAIWAN-CA(TWCA) JCICSecurityTool fails to check the source website and access locations when executing multiple Registr... |
| CVE-2023-48384 | CRITICAL | 9.8 | 1.1% | Dec 15, 2023 | ArmorX Global Technology Corporation ArmorX Spam has insufficient validation for user input within a special function. A... |
| CVE-2023-48382 | MEDIUM | 6.5 | 0.6% | Dec 15, 2023 | Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a mail de... |
| CVE-2023-48381 | MEDIUM | 6.5 | 0.6% | Dec 15, 2023 | Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a special... |
| CVE-2023-48380 | HIGH | 8 | 0.7% | Dec 15, 2023 | Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a... |
| CVE-2023-46279 | CRITICAL | 9.8 | 1.7% | Dec 15, 2023 | Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are r... |
| CVE-2023-29234 | CRITICAL | 9.8 | 7.4% | Dec 15, 2023 | A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 thro... |
| CVE-2023-6827 | HIGH | 8.8 | 1.3% | Dec 15, 2023 | The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type val... |
| CVE-2023-6826 | HIGH | 7.2 | 1.3% | Dec 15, 2023 | The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the '... |
| CVE-2023-48379 | MEDIUM | 5.3 | 0.6% | Dec 15, 2023 | Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter withi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now