2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37134 | MEDIUM | 5.4 | 0.3% | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to ... |
| CVE-2023-37133 | MEDIUM | 5.4 | 0.3% | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to ... |
| CVE-2023-37132 | MEDIUM | 5.4 | 0.3% | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to e... |
| CVE-2023-37131 | MEDIUM | 6.5 | 0.2% | Jul 6, 2023 | A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers... |
| CVE-2023-37125 | MEDIUM | 5.4 | 0.3% | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers... |
| CVE-2023-37124 | MEDIUM | 5.4 | 0.3% | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute a... |
| CVE-2023-37122 | MEDIUM | 5.4 | 0.3% | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or... |
| CVE-2023-36970 | MEDIUM | 5.4 | 0.5% | Jul 6, 2023 | A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web sc... |
| CVE-2023-35948 | MEDIUM | 6.1 | 0.3% | Jul 6, 2023 | Novu provides an API for sending notifications through multiple channels. Versions prior to 0.16.0 contain an open redir... |
| CVE-2023-30326 | MEDIUM | 6.1 | 0.4% | Jul 6, 2023 | Cross Site Scripting (XSS) vulnerability in username field in /WebContent/WEB-INF/lib/chatbox.jsp in wliang6 ChatEngine ... |
| CVE-2023-30322 | MEDIUM | 5.4 | 0.4% | Jul 6, 2023 | Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0... |
| CVE-2023-24497 | MEDIUM | 4.7 | 0.7% | Jul 6, 2023 | Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN ... |
| CVE-2023-24496 | MEDIUM | 4.7 | 0.7% | Jul 6, 2023 | Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN ... |
| CVE-2023-23547 | MEDIUM | 6.5 | 1.1% | Jul 6, 2023 | A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A... |
| CVE-2023-36995 | MEDIUM | 6.1 | 0.4% | Jul 6, 2023 | TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, ... |
| CVE-2023-3456 | MEDIUM | 5.3 | 0.3% | Jul 6, 2023 | Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability ... |
| CVE-2023-37238 | MEDIUM | 5.3 | 0.3% | Jul 6, 2023 | Vulnerability of apps' permission to access a certain API being incompletely verified in the wireless projection module.... |
| CVE-2023-26138 | MEDIUM | 4.3 | 0.4% | Jul 6, 2023 | All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to... |
| CVE-2023-26137 | MEDIUM | 6.1 | 0.4% | Jul 6, 2023 | All versions of the package drogonframework/drogon are vulnerable to HTTP Response Splitting when untrusted user input i... |
| CVE-2023-30678 | MEDIUM | 5.5 | 0.2% | Jul 6, 2023 | Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows atta... |
| CVE-2023-30677 | MEDIUM | 4.6 | 0.2% | Jul 6, 2023 | Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data... |
| CVE-2023-30676 | MEDIUM | 4.6 | 0.2% | Jul 6, 2023 | Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data... |
| CVE-2023-30675 | MEDIUM | 5.5 | 0.2% | Jul 6, 2023 | Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account informa... |
| CVE-2023-30674 | MEDIUM | 6.5 | 0.5% | Jul 6, 2023 | Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass SameSite Cookie. |
| CVE-2023-30673 | MEDIUM | 5.5 | 0.1% | Jul 6, 2023 | Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.23052_1 allows local attack... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now