2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48205 | MEDIUM | 5.3 | 0.8% | Dec 7, 2023 | Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emai... |
| CVE-2023-43304 | HIGH | 8.2 | 0.5% | Dec 7, 2023 | An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of... |
| CVE-2023-43303 | HIGH | 8.2 | 0.5% | Dec 7, 2023 | An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via l... |
| CVE-2023-43302 | HIGH | 8.2 | 0.6% | Dec 7, 2023 | An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the ... |
| CVE-2023-43301 | HIGH | 8.2 | 0.6% | Dec 7, 2023 | An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leaka... |
| CVE-2023-43300 | HIGH | 8.2 | 0.5% | Dec 7, 2023 | An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage ... |
| CVE-2023-43299 | MEDIUM | 5.3 | 0.5% | Dec 7, 2023 | An issue in DA BUTCHERS mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of... |
| CVE-2023-43298 | MEDIUM | 5.3 | 0.5% | Dec 7, 2023 | An issue in SCOL Members Card mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leak... |
| CVE-2023-48172 | MEDIUM | 5.4 | 0.7% | Dec 7, 2023 | A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript... |
| CVE-2023-46916 | MEDIUM | 4.3 | 0.5% | Dec 7, 2023 | Maxima Max Pro Power 1.0 486A devices allow BLE traffic replay. An attacker can use GATT characteristic handle 0x0012 to... |
| CVE-2023-46857 | MEDIUM | 5.4 | 0.6% | Dec 7, 2023 | Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomp... |
| CVE-2023-46307 | HIGH | 7.5 | 1.3% | Dec 7, 2023 | An issue was discovered in server.js in etcd-browser 87ae63d75260. By supplying a /../../../ Directory Traversal input t... |
| CVE-2023-43103 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | An XSS issue was discovered in a web endpoint in Zimbra Collaboration (ZCS) before 10.0.4 via an unsanitized parameter. ... |
| CVE-2023-43102 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox... |
| CVE-2023-6568 | MEDIUM | 6.1 | 1.6% | Dec 7, 2023 | A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the han... |
| CVE-2023-41913 | CRITICAL | 9.8 | 2.3% | Dec 7, 2023 | strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value ... |
| CVE-2023-41106 | HIGH | 7.5 | 0.9% | Dec 7, 2023 | An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3. An attacker can gain access to a Zimbra account. Th... |
| CVE-2023-28017 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbi... |
| CVE-2023-40238 | MEDIUM | 5.5 | 1.9% | Dec 7, 2023 | A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.4... |
| CVE-2023-5761 | HIGH | 7.5 | 0.7% | Dec 7, 2023 | The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via ... |
| CVE-2023-5714 | MEDIUM | 4.3 | 0.4% | Dec 7, 2023 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2023-5713 | MEDIUM | 4.3 | 0.5% | Dec 7, 2023 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2023-5712 | MEDIUM | 4.3 | 0.4% | Dec 7, 2023 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2023-5711 | MEDIUM | 4.3 | 0.4% | Dec 7, 2023 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2023-5710 | MEDIUM | 4.3 | 0.5% | Dec 7, 2023 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now