2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29546 | MEDIUM | 6.5 | 0.5% | Jun 19, 2023 | When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden,... |
| CVE-2023-29545 | MEDIUM | 6.5 | 0.6% | Jun 19, 2023 | Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable n... |
| CVE-2023-0489 | MEDIUM | 5.4 | 0.4% | Jun 19, 2023 | The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outp... |
| CVE-2023-0368 | MEDIUM | 5.4 | 0.4% | Jun 19, 2023 | The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate ... |
| CVE-2023-32210 | MEDIUM | 6.5 | 0.5% | Jun 19, 2023 | Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately priv... |
| CVE-2023-32208 | MEDIUM | 5.3 | 0.5% | Jun 19, 2023 | Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects Firefox < 113. |
| CVE-2023-29532 | MEDIUM | 5.5 | 0.2% | Jun 19, 2023 | A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service... |
| CVE-2023-35005 | MEDIUM | 6.5 | 1.5% | Jun 19, 2023 | In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerabi... |
| CVE-2023-35866 | MEDIUM | 5.5 | 0.2% | Jun 19, 2023 | In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master passwo... |
| CVE-2023-35862 | MEDIUM | 6.5 | 0.8% | Jun 19, 2023 | libcoap 4.3.1 contains a buffer over-read via the function coap_parse_oscore_conf_mem at coap_oscore.c. |
| CVE-2023-34657 | MEDIUM | 4.8 | 0.4% | Jun 19, 2023 | A stored cross-site scripting (XSS) vulnerability in Eyoucms v1.6.2 allows attackers to execute arbitrary web scripts or... |
| CVE-2023-35840 | MEDIUM | 6.5 | 1.9% | Jun 19, 2023 | _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVol... |
| CVE-2023-3311 | MEDIUM | 5.4 | 0.6% | Jun 18, 2023 | A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. T... |
| CVE-2023-3309 | MEDIUM | 5.4 | 0.6% | Jun 18, 2023 | A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vu... |
| CVE-2023-34459 | MEDIUM | 5.9 | 0.4% | Jun 16, 2023 | OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2... |
| CVE-2023-35789 | MEDIUM | 5.5 | 0.2% | Jun 16, 2023 | An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only ... |
| CVE-2023-33438 | MEDIUM | 5.4 | 0.5% | Jun 16, 2023 | A stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to injec... |
| CVE-2023-30904 | MEDIUM | 5.5 | 0.2% | Jun 16, 2023 | A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information... |
| CVE-2023-30903 | MEDIUM | 5.5 | 0.2% | Jun 16, 2023 | HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6... |
| CVE-2023-3195 | MEDIUM | 5.5 | 0.5% | Jun 16, 2023 | A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the ... |
| CVE-2023-34475 | MEDIUM | 5.5 | 0.4% | Jun 16, 2023 | A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attac... |
| CVE-2023-34474 | MEDIUM | 5.5 | 0.4% | Jun 16, 2023 | A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A loca... |
| CVE-2023-34660 | MEDIUM | 6.5 | 0.6% | Jun 16, 2023 | jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface. |
| CVE-2023-34733 | MEDIUM | 6.8 | 0.5% | Jun 16, 2023 | A lack of exception handling in the Volkswagen Discover Media Infotainment System Software Version 0876 allows attackers... |
| CVE-2023-30453 | MEDIUM | 5.4 | 0.3% | Jun 16, 2023 | The Teamlead Reminder plugin through 2.6.5 for Jira allows persistent XSS via the message parameter. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now