2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0757 | CRITICAL | 9.8 | 0.9% | Dec 14, 2023 | Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProCon... |
| CVE-2023-6571 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | Cross-site Scripting (XSS) - Reflected in kubeflow/kubeflow |
| CVE-2023-6570 | MEDIUM | 6.5 | 0.6% | Dec 14, 2023 | Server-Side Request Forgery (SSRF) in kubeflow/kubeflow |
| CVE-2023-6569 | HIGH | 8.2 | 0.7% | Dec 14, 2023 | External Control of File Name or Path in h2oai/h2o-3 |
| CVE-2023-50371 | MEDIUM | 5.4 | 0.4% | Dec 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Page Visit Counter... |
| CVE-2023-48631 | HIGH | 7.5 | 1.1% | Dec 14, 2023 | @adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result... |
| CVE-2023-49708 | CRITICAL | 9.8 | 0.8% | Dec 14, 2023 | SQLi vulnerability in Starshop component for Joomla. |
| CVE-2023-49707 | CRITICAL | 9.8 | 0.8% | Dec 14, 2023 | SQLi vulnerability in S5 Register module for Joomla. |
| CVE-2023-48925 | CRITICAL | 9.8 | 0.5% | Dec 14, 2023 | SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and o... |
| CVE-2023-46750 | MEDIUM | 6.1 | 1.5% | Dec 14, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mi... |
| CVE-2023-46348 | CRITICAL | 9.8 | 0.8% | Dec 14, 2023 | SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain ... |
| CVE-2023-40659 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla. |
| CVE-2023-40658 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla. |
| CVE-2023-40657 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla. |
| CVE-2023-40656 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the Quickform component for Joomla. |
| CVE-2023-40655 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the Proforms Basic component for Joomla. |
| CVE-2023-40630 | CRITICAL | 9.8 | 0.7% | Dec 14, 2023 | Unauthenticated LFI/SSRF in JCDashboards component for Joomla. |
| CVE-2023-40629 | CRITICAL | 9.8 | 0.8% | Dec 14, 2023 | SQLi vulnerability in LMS Lite component for Joomla. |
| CVE-2023-40628 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the Extplorer component for Joomla. |
| CVE-2023-40627 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | A reflected XSS vulnerability was discovered in the LivingWord component for Joomla. |
| CVE-2023-25644 | HIGH | 7.5 | 0.7% | Dec 14, 2023 | There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web ... |
| CVE-2023-25643 | HIGH | 8.8 | 1.8% | Dec 14, 2023 | There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation... |
| CVE-2023-25642 | MEDIUM | 6.5 | 0.5% | Dec 14, 2023 | There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp p... |
| CVE-2023-1904 | HIGH | 7.5 | 0.4% | Dec 14, 2023 | In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the... |
| CVE-2023-48085 | CRITICAL | 9.8 | 75.8% | Dec 14, 2023 | Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now