2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34222 | MEDIUM | 6.1 | 1.0% | May 31, 2023 | In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible |
| CVE-2023-34221 | MEDIUM | 5.4 | 1.0% | May 31, 2023 | In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible |
| CVE-2023-34220 | MEDIUM | 5.4 | 61.2% | May 31, 2023 | In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible |
| CVE-2023-34219 | MEDIUM | 4.3 | 0.4% | May 31, 2023 | In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Bu... |
| CVE-2023-31548 | MEDIUM | 5.4 | 1.2% | May 31, 2023 | A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attac... |
| CVE-2023-26842 | MEDIUM | 5.4 | 1.4% | May 31, 2023 | A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web scr... |
| CVE-2023-3009 | MEDIUM | 5.4 | 0.7% | May 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. |
| CVE-2023-33736 | MEDIUM | 5.4 | 0.4% | May 31, 2023 | A stored cross-site scripting (XSS) vulnerability in Dcat-Admin v2.1.3-beta allows attackers to execute arbitrary web sc... |
| CVE-2023-3005 | MEDIUM | 6.1 | 0.6% | May 31, 2023 | A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management... |
| CVE-2023-2304 | MEDIUM | 5.4 | 0.7% | May 31, 2023 | The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_favorites' shortcode in ve... |
| CVE-2023-26131 | MEDIUM | 6.1 | 0.7% | May 31, 2023 | All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/... |
| CVE-2023-2836 | MEDIUM | 4.8 | 0.6% | May 31, 2023 | The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up t... |
| CVE-2023-1661 | MEDIUM | 5.4 | 0.4% | May 31, 2023 | The Display post meta, term meta, comment meta, and user meta plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2023-2547 | MEDIUM | 5.4 | 0.4% | May 31, 2023 | The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check... |
| CVE-2023-2436 | MEDIUM | 4.4 | 0.5% | May 31, 2023 | The Blog-in-Blog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blog_in_blog' shortcode in v... |
| CVE-2023-2999 | MEDIUM | 6.1 | 0.5% | May 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14. |
| CVE-2023-2998 | MEDIUM | 6.1 | 0.5% | May 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14. |
| CVE-2023-23562 | MEDIUM | 4.3 | 0.4% | May 31, 2023 | Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can upd... |
| CVE-2023-2612 | MEDIUM | 4.7 | 0.3% | May 31, 2023 | Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when ... |
| CVE-2023-28350 | MEDIUM | 6.1 | 1.1% | May 31, 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized be... |
| CVE-2023-28345 | MEDIUM | 4.6 | 0.3% | May 31, 2023 | An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the t... |
| CVE-2023-2952 | MEDIUM | 6.5 | 1.1% | May 30, 2023 | XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injectio... |
| CVE-2023-34151 | MEDIUM | 5.5 | 1.0% | May 30, 2023 | A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size... |
| CVE-2023-33962 | MEDIUM | 6.1 | 0.6% | May 30, 2023 | JStachio is a type-safe Java Mustache templating engine. Prior to version 1.0.1, JStachio fails to escape single quotes... |
| CVE-2023-33961 | MEDIUM | 5.4 | 0.4% | May 30, 2023 | Leantime is a lean open source project management system. Starting in version 2.3.21, an authenticated user with comment... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now