2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25781 | MEDIUM | 4.8 | 0.4% | May 26, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sebastian Krysmanski Upload File Type Settings plugin ... |
| CVE-2023-2903 | MEDIUM | 6.5 | 0.7% | May 25, 2023 | A vulnerability classified as problematic has been found in NFine Rapid Development Platform 20230511. This affects an u... |
| CVE-2023-31147 | MEDIUM | 6.5 | 0.9% | May 25, 2023 | c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to g... |
| CVE-2023-31130 | MEDIUM | 6.4 | 0.3% | May 25, 2023 | c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 ad... |
| CVE-2023-2902 | MEDIUM | 6.5 | 0.7% | May 25, 2023 | A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by th... |
| CVE-2023-2901 | MEDIUM | 6.5 | 0.7% | May 25, 2023 | A vulnerability was found in NFine Rapid Development Platform 20230511. It has been declared as problematic. Affected by... |
| CVE-2023-2804 | MEDIUM | 6.5 | 1.2% | May 25, 2023 | A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrge... |
| CVE-2023-2255 | MEDIUM | 5.3 | 2.2% | May 25, 2023 | Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a docum... |
| CVE-2023-25439 | MEDIUM | 6.1 | 2.2% | May 25, 2023 | Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitr... |
| CVE-2023-26215 | MEDIUM | 6.5 | 0.7% | May 25, 2023 | The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with lo... |
| CVE-2023-30851 | MEDIUM | 5.3 | 0.7% | May 25, 2023 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users... |
| CVE-2023-30615 | MEDIUM | 5.4 | 0.4% | May 25, 2023 | Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations.... |
| CVE-2023-33751 | MEDIUM | 5.4 | 0.4% | May 25, 2023 | A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or H... |
| CVE-2023-33750 | MEDIUM | 5.4 | 0.4% | May 25, 2023 | A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or H... |
| CVE-2023-32694 | MEDIUM | 5.4 | 0.3% | May 25, 2023 | Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing ... |
| CVE-2023-33356 | MEDIUM | 5.4 | 0.4% | May 25, 2023 | IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2023-22504 | MEDIUM | 6.5 | 0.7% | May 25, 2023 | Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not wri... |
| CVE-2023-0459 | MEDIUM | 5.5 | 0.6% | May 25, 2023 | Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to b... |
| CVE-2023-28370 | MEDIUM | 6.1 | 1.1% | May 25, 2023 | Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a... |
| CVE-2023-2886 | MEDIUM | 4.3 | 0.2% | May 25, 2023 | Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipu... |
| CVE-2023-2881 | MEDIUM | 4.9 | 0.5% | May 25, 2023 | Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10. |
| CVE-2023-1158 | MEDIUM | 4.3 | 0.4% | May 24, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard... |
| CVE-2023-33829 | MEDIUM | 5.4 | 7.3% | May 24, 2023 | A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute... |
| CVE-2023-33800 | MEDIUM | 5.4 | 0.4% | May 24, 2023 | A stored cross-site scripting (XSS) vulnerability in the Create Regions (/dcim/regions/) function of Netbox v3.5.1 allow... |
| CVE-2023-33799 | MEDIUM | 5.4 | 0.4% | May 24, 2023 | A stored cross-site scripting (XSS) vulnerability in the Create Contacts (/tenancy/contacts/) function of Netbox v3.5.1 ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now