2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32573 | MEDIUM | 6.5 | 0.9% | May 10, 2023 | In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerE... |
| CVE-2023-30777 | MEDIUM | 6.1 | 38.8% | May 10, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced C... |
| CVE-2023-2615 | MEDIUM | 5.4 | 0.5% | May 10, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21. |
| CVE-2023-2614 | MEDIUM | 5.4 | 0.5% | May 10, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21. |
| CVE-2023-27919 | MEDIUM | 5.3 | 0.7% | May 10, 2023 | Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a rem... |
| CVE-2023-27918 | MEDIUM | 6.1 | 0.5% | May 10, 2023 | Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.... |
| CVE-2023-27888 | MEDIUM | 5.4 | 0.4% | May 10, 2023 | Cross-site scripting vulnerability in Joruri Gw Ver 3.2.5 and earlier allows a remote authenticated attacker to inject a... |
| CVE-2023-25070 | MEDIUM | 6.5 | 0.5% | May 10, 2023 | Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the ... |
| CVE-2023-24586 | MEDIUM | 6.5 | 0.5% | May 10, 2023 | Cleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may al... |
| CVE-2023-23901 | MEDIUM | 6.5 | 0.5% | May 10, 2023 | Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and... |
| CVE-2023-22361 | MEDIUM | 6.5 | 35.9% | May 10, 2023 | Improper privilege management vulnerability in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier allows a remote aut... |
| CVE-2023-32570 | MEDIUM | 5.9 | 0.7% | May 10, 2023 | VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_d... |
| CVE-2023-2616 | MEDIUM | 5.4 | 0.5% | May 10, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21. |
| CVE-2023-26126 | MEDIUM | 5.3 | 1.0% | May 10, 2023 | All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the pat... |
| CVE-2023-25833 | MEDIUM | 5.4 | 0.4% | May 10, 2023 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, auth... |
| CVE-2023-28318 | MEDIUM | 5.3 | 0.3% | May 9, 2023 | A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory o... |
| CVE-2023-28317 | MEDIUM | 5.3 | 0.2% | May 9, 2023 | A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing th... |
| CVE-2023-28126 | MEDIUM | 5.9 | 66.7% | May 9, 2023 | An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain... |
| CVE-2023-28125 | MEDIUM | 5.9 | 2.3% | May 9, 2023 | An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attack... |
| CVE-2023-30057 | MEDIUM | 5.4 | 0.6% | May 9, 2023 | Multiple stored cross-site scripting (XSS) vulnerabilities in FICO Origination Manager Decision Module 4.8.1 allow attac... |
| CVE-2023-25831 | MEDIUM | 6.1 | 0.5% | May 9, 2023 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unau... |
| CVE-2023-2609 | MEDIUM | 5.5 | 0.5% | May 9, 2023 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531. |
| CVE-2023-29338 | MEDIUM | 6.6 | 0.9% | May 9, 2023 | Visual Studio Code Spoofing Vulnerability |
| CVE-2023-29324 | MEDIUM | 6.5 | 2.8% | May 9, 2023 | Windows MSHTML Platform Security Feature Bypass Vulnerability |
| CVE-2023-28290 | MEDIUM | 5.3 | 1.2% | May 9, 2023 | Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now