2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21142 | MEDIUM | 5.5 | 0.1% | Jun 15, 2023 | In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead... |
| CVE-2023-21141 | MEDIUM | 5.5 | 0.1% | Jun 15, 2023 | In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypa... |
| CVE-2023-21137 | MEDIUM | 5.5 | 0.1% | Jun 15, 2023 | In several methods of JobStore.java, uncaught exceptions in job map parsing could lead to local persistent denial of ser... |
| CVE-2023-21136 | MEDIUM | 5.5 | 0.1% | Jun 15, 2023 | In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input valida... |
| CVE-2023-21105 | MEDIUM | 5.5 | 0.1% | Jun 15, 2023 | In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This ... |
| CVE-2023-21095 | MEDIUM | 4.7 | 0.1% | Jun 15, 2023 | In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen bypass due to a rac... |
| CVE-2023-34833 | MEDIUM | 6.1 | 0.5% | Jun 15, 2023 | An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arb... |
| CVE-2023-34666 | MEDIUM | 6.1 | 0.7% | Jun 15, 2023 | Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to injec... |
| CVE-2023-34626 | MEDIUM | 4.3 | 0.5% | Jun 15, 2023 | Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function. |
| CVE-2023-24420 | MEDIUM | 6.1 | 0.4% | Jun 15, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact F... |
| CVE-2023-25972 | MEDIUM | 4.8 | 0.4% | Jun 15, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in IKSWEB WordPress Старт plugin <= 3.7 versions. |
| CVE-2023-32229 | MEDIUM | 6.5 | 0.6% | Jun 15, 2023 | Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the ... |
| CVE-2023-3193 | MEDIUM | 6.1 | 0.5% | Jun 15, 2023 | Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4... |
| CVE-2023-35029 | MEDIUM | 6.1 | 0.5% | Jun 15, 2023 | Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Li... |
| CVE-2023-34452 | MEDIUM | 6.1 | 0.6% | Jun 14, 2023 | Grav is a flat-file content management system. In versions 1.7.42 and prior, the "/forgot_password" page has a self-refl... |
| CVE-2023-2820 | MEDIUM | 6.8 | 0.3% | Jun 14, 2023 | An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (... |
| CVE-2023-2819 | MEDIUM | 4.3 | 0.3% | Jun 14, 2023 | A stored cross-site scripting vulnerability in the Sources UI in Proofpoint Threat Response/ Threat Response Auto Pull (... |
| CVE-2023-34565 | MEDIUM | 5.4 | 0.4% | Jun 14, 2023 | Netbox 3.5.1 is vulnerable to Cross Site Scripting (XSS) in the "Create Wireless LAN Groups" function. |
| CVE-2023-34449 | MEDIUM | 5.3 | 1.0% | Jun 14, 2023 | ink! is an embedded domain specific language to write smart contracts in Rust for blockchains built on the Substrate fra... |
| CVE-2023-33515 | MEDIUM | 5.4 | 0.4% | Jun 14, 2023 | SoftExpert Excellence Suite 2.1.9 is vulnerable to Cross Site Scripting (XSS) via query screens. |
| CVE-2023-26965 | MEDIUM | 5.5 | 0.4% | Jun 14, 2023 | loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image. |
| CVE-2023-34367 | MEDIUM | 6.5 | 1.2% | Jun 14, 2023 | Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows unti... |
| CVE-2023-0010 | MEDIUM | 5.4 | 0.4% | Jun 14, 2023 | A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software... |
| CVE-2023-35116 | MEDIUM | 4.7 | 0.4% | Jun 14, 2023 | jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted ... |
| CVE-2023-34824 | MEDIUM | 5.5 | 0.3% | Jun 14, 2023 | fdkaac before 1.0.5 was discovered to contain a heap buffer overflow in caf_info function in caf_reader.c. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now