2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2671 | MEDIUM | 6.1 | 0.6% | May 12, 2023 | A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been rated as problematic. Thi... |
| CVE-2023-2674 | MEDIUM | 4.3 | 0.6% | May 12, 2023 | Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. |
| CVE-2023-28936 | MEDIUM | 5.3 | 1.2% | May 12, 2023 | Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeet... |
| CVE-2023-2667 | MEDIUM | 6.1 | 0.7% | May 12, 2023 | A vulnerability has been found in SourceCodester Lost and Found Information System 1.0 and classified as problematic. Af... |
| CVE-2023-28520 | MEDIUM | 5.4 | 0.4% | May 12, 2023 | IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2023-29808 | MEDIUM | 6.1 | 1.4% | May 12, 2023 | Cross Site Scripting (XSS) vulnerability in vogtmh cmaps (companymaps) 8.0 allows attackers to execute arbitrary code. |
| CVE-2023-29286 | MEDIUM | 5.5 | 0.3% | May 11, 2023 | Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability ... |
| CVE-2023-29279 | MEDIUM | 5.5 | 0.3% | May 11, 2023 | Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability that could le... |
| CVE-2023-29277 | MEDIUM | 5.5 | 0.3% | May 11, 2023 | Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability that could le... |
| CVE-2023-28361 | MEDIUM | 6.5 | 0.3% | May 11, 2023 | A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to acc... |
| CVE-2023-28360 | MEDIUM | 4.3 | 0.8% | May 11, 2023 | An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user... |
| CVE-2023-28359 | MEDIUM | 5.3 | 0.6% | May 11, 2023 | A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be e... |
| CVE-2023-28358 | MEDIUM | 6.1 | 0.4% | May 11, 2023 | A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allow... |
| CVE-2023-28357 | MEDIUM | 4.3 | 0.4% | May 11, 2023 | A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking... |
| CVE-2023-28325 | MEDIUM | 6.5 | 0.4% | May 11, 2023 | An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid param... |
| CVE-2023-2664 | MEDIUM | 5.5 | 0.3% | May 11, 2023 | In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflo... |
| CVE-2023-2663 | MEDIUM | 5.5 | 0.5% | May 11, 2023 | In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow. ... |
| CVE-2023-2662 | MEDIUM | 5.5 | 0.3% | May 11, 2023 | In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero. |
| CVE-2023-29791 | MEDIUM | 6.1 | 0.4% | May 11, 2023 | kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information. |
| CVE-2023-32082 | MEDIUM | 4.3 | 0.7% | May 11, 2023 | etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the Leas... |
| CVE-2023-29195 | MEDIUM | 4.3 | 1.0% | May 11, 2023 | Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16... |
| CVE-2023-27870 | MEDIUM | 5.9 | 0.7% | May 11, 2023 | IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a downl... |
| CVE-2023-27554 | MEDIUM | 6.3 | 0.9% | May 11, 2023 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when proces... |
| CVE-2023-30394 | MEDIUM | 6.1 | 0.6% | May 11, 2023 | The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this is... |
| CVE-2023-29029 | MEDIUM | 5.9 | 0.6% | May 11, 2023 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potenti... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now