2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25730 | MEDIUM | 5.4 | 0.5% | Jun 2, 2023 | A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser in... |
| CVE-2023-25728 | MEDIUM | 6.5 | 0.7% | Jun 2, 2023 | The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted ... |
| CVE-2023-23604 | MEDIUM | 6.5 | 0.5% | Jun 2, 2023 | A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromS... |
| CVE-2023-23603 | MEDIUM | 6.5 | 0.6% | Jun 2, 2023 | Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` w... |
| CVE-2023-23602 | MEDIUM | 6.5 | 0.6% | Jun 2, 2023 | A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src head... |
| CVE-2023-23601 | MEDIUM | 6.5 | 0.3% | Jun 2, 2023 | Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to webs... |
| CVE-2023-23600 | MEDIUM | 6.5 | 0.5% | Jun 2, 2023 | Per origin notification permissions were being stored in a way that didn't take into account what browsing context the p... |
| CVE-2023-23599 | MEDIUM | 6.5 | 0.6% | Jun 2, 2023 | When copying a network request from the developer tools panel as a curl command the output was not being properly saniti... |
| CVE-2023-23598 | MEDIUM | 6.5 | 0.6% | Jun 2, 2023 | Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing f... |
| CVE-2023-23597 | MEDIUM | 6.5 | 0.3% | Jun 2, 2023 | A compromised web child process could disable web security opening restrictions, leading to a new child process being sp... |
| CVE-2023-1945 | MEDIUM | 6.5 | 0.6% | Jun 2, 2023 | Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable cr... |
| CVE-2023-0616 | MEDIUM | 6.5 | 0.5% | Jun 2, 2023 | If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and d... |
| CVE-2023-0547 | MEDIUM | 6.5 | 0.4% | Jun 2, 2023 | OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certif... |
| CVE-2023-0430 | MEDIUM | 6.5 | 0.4% | Jun 2, 2023 | Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certific... |
| CVE-2023-3067 | MEDIUM | 5.4 | 0.4% | Jun 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4. |
| CVE-2023-34094 | MEDIUM | 5.3 | 0.6% | Jun 2, 2023 | ChuanhuChatGPT is a graphical user interface for ChatGPT and many large language models. A vulnerability in versions 202... |
| CVE-2023-3060 | MEDIUM | 5.4 | 0.6% | Jun 2, 2023 | A vulnerability has been found in code-projects Agro-School Management System 1.0 and classified as problematic. This vu... |
| CVE-2023-3058 | MEDIUM | 5.4 | 0.6% | Jun 2, 2023 | A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unkn... |
| CVE-2023-3031 | MEDIUM | 4.9 | 0.8% | Jun 2, 2023 | Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowi... |
| CVE-2023-33731 | MEDIUM | 6.1 | 0.8% | Jun 2, 2023 | Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management co... |
| CVE-2023-33717 | MEDIUM | 5.5 | 0.3% | Jun 2, 2023 | mp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBytes() had allocated memory but... |
| CVE-2023-28469 | MEDIUM | 5.5 | 0.2% | Jun 2, 2023 | An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat... |
| CVE-2023-28705 | MEDIUM | 6.1 | 0.4% | Jun 2, 2023 | Openfind Mail2000 has insufficient filtering special characters of email content of its content filtering function. A re... |
| CVE-2023-28700 | MEDIUM | 6.8 | 0.3% | Jun 2, 2023 | OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area ... |
| CVE-2023-25780 | MEDIUM | 5.7 | 0.3% | Jun 2, 2023 | It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now