2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31285 | MEDIUM | 6.1 | 0.8% | Apr 27, 2023 | An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some sp... |
| CVE-2023-22901 | MEDIUM | 4.9 | 0.9% | Apr 27, 2023 | ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit... |
| CVE-2023-25292 | MEDIUM | 6.1 | 0.8% | Apr 27, 2023 | Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated pr... |
| CVE-2023-1786 | MEDIUM | 5.5 | 0.3% | Apr 26, 2023 | Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to f... |
| CVE-2023-30843 | MEDIUM | 6.5 | 0.6% | Apr 26, 2023 | Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access t... |
| CVE-2023-29443 | MEDIUM | 4.9 | 3.0% | Apr 26, 2023 | Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and... |
| CVE-2023-29442 | MEDIUM | 6.1 | 9.4% | Apr 26, 2023 | Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS. |
| CVE-2023-29836 | MEDIUM | 6.1 | 0.6% | Apr 26, 2023 | Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attack... |
| CVE-2023-31250 | MEDIUM | 6.5 | 0.5% | Apr 26, 2023 | The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gain... |
| CVE-2023-30841 | MEDIUM | 5.5 | 0.2% | Apr 26, 2023 | Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic an... |
| CVE-2023-26930 | MEDIUM | 5.5 | 0.3% | Apr 26, 2023 | Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc... |
| CVE-2023-0458 | MEDIUM | 4.7 | 0.7% | Apr 26, 2023 | A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument... |
| CVE-2023-30212 | MEDIUM | 6.1 | 8.1% | Apr 26, 2023 | OURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php. |
| CVE-2023-2307 | MEDIUM | 6.5 | 0.3% | Apr 26, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0. |
| CVE-2023-30210 | MEDIUM | 6.1 | 1.2% | Apr 26, 2023 | OURPHP <= 7.2.0 is vulnerable to Cross Site Scripting (XSS) via ourphp_tz.php. |
| CVE-2023-22729 | MEDIUM | 6.1 | 0.4% | Apr 26, 2023 | Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Pr... |
| CVE-2023-30267 | MEDIUM | 6.1 | 0.4% | Apr 26, 2023 | CLTPHP <=6.0 is vulnerable to Cross Site Scripting (XSS) via application/home/controller/Changyan.php. |
| CVE-2023-30265 | MEDIUM | 6.5 | 1.0% | Apr 26, 2023 | CLTPHP <=6.0 is vulnerable to Directory Traversal. |
| CVE-2023-22728 | MEDIUM | 4.3 | 0.5% | Apr 26, 2023 | Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Pr... |
| CVE-2023-2294 | MEDIUM | 6.1 | 0.5% | Apr 26, 2023 | A vulnerability was found in UCMS 1.6.0. It has been classified as problematic. This affects an unknown part of the file... |
| CVE-2023-30111 | MEDIUM | 6.1 | 0.4% | Apr 26, 2023 | Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2023-30106 | MEDIUM | 6.1 | 0.5% | Apr 26, 2023 | Sourcecodester Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS) via page=about. |
| CVE-2023-26560 | MEDIUM | 6.5 | 0.5% | Apr 26, 2023 | Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports... |
| CVE-2023-31223 | MEDIUM | 5.4 | 0.5% | Apr 25, 2023 | Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars. |
| CVE-2023-20870 | MEDIUM | 6 | 0.4% | Apr 25, 2023 | VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing h... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now