2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33943 | MEDIUM | 5.4 | 0.4% | May 24, 2023 | Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay ... |
| CVE-2023-33942 | MEDIUM | 5.4 | 0.5% | May 24, 2023 | Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal ... |
| CVE-2023-33941 | MEDIUM | 6.1 | 0.5% | May 24, 2023 | Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedire... |
| CVE-2023-33940 | MEDIUM | 5.4 | 0.5% | May 24, 2023 | Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Lifera... |
| CVE-2023-33939 | MEDIUM | 5.4 | 0.5% | May 24, 2023 | Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 through 7.4.3.12, and Life... |
| CVE-2023-33938 | MEDIUM | 6.1 | 0.5% | May 24, 2023 | Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 ... |
| CVE-2023-33937 | MEDIUM | 5.4 | 0.4% | May 24, 2023 | Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and ... |
| CVE-2023-2864 | MEDIUM | 6.1 | 0.5% | May 24, 2023 | A vulnerability was found in SourceCodester Online Jewelry Store 1.0 and classified as problematic. Affected by this iss... |
| CVE-2023-2863 | MEDIUM | 5.5 | 0.2% | May 24, 2023 | A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affec... |
| CVE-2023-2862 | MEDIUM | 6.1 | 0.6% | May 24, 2023 | A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown fu... |
| CVE-2023-2498 | MEDIUM | 5.4 | 0.4% | May 24, 2023 | The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2023-28015 | MEDIUM | 5.3 | 0.4% | May 23, 2023 | The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability. During a failed log... |
| CVE-2023-31860 | MEDIUM | 5.4 | 0.4% | May 23, 2023 | Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system. |
| CVE-2023-31518 | MEDIUM | 5.5 | 0.3% | May 23, 2023 | A heap use-after-free in the component CDataFileReader::GetItem of teeworlds v0.7.5 allows attackers to cause a Denial o... |
| CVE-2023-1209 | MEDIUM | 5.4 | 0.4% | May 23, 2023 | Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbi... |
| CVE-2023-33599 | MEDIUM | 6.1 | 0.4% | May 23, 2023 | EasyImages2.0 ≤ 2.8.1 is vulnerable to Cross Site Scripting (XSS) via viewlog.php. |
| CVE-2023-33359 | MEDIUM | 4.3 | 0.4% | May 23, 2023 | Piwigo 13.6.0 is vulnerable to Cross Site Request Forgery (CSRF) in the "add tags" function. |
| CVE-2023-31669 | MEDIUM | 5.5 | 0.3% | May 23, 2023 | WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote ("). |
| CVE-2023-2844 | MEDIUM | 4.9 | 0.7% | May 23, 2023 | Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1... |
| CVE-2023-30469 | MEDIUM | 6.1 | 0.4% | May 23, 2023 | Cross-site Scripting vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component) al... |
| CVE-2023-28390 | MEDIUM | 6.8 | 0.3% | May 23, 2023 | Privilege escalation vulnerability in SR-7100VN firmware Ver.1.38(N) and earlier and SR-7100VN #31 firmware Ver.1.21 and... |
| CVE-2023-28367 | MEDIUM | 5.4 | 0.6% | May 23, 2023 | Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a re... |
| CVE-2023-27926 | MEDIUM | 5.4 | 0.6% | May 23, 2023 | Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allo... |
| CVE-2023-27925 | MEDIUM | 5.4 | 0.6% | May 23, 2023 | Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and ear... |
| CVE-2023-27923 | MEDIUM | 5.4 | 0.6% | May 23, 2023 | Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now