2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2281 | MEDIUM | 4.3 | 0.5% | Apr 25, 2023 | When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. Thi... |
| CVE-2023-30417 | MEDIUM | 5.4 | 0.4% | Apr 25, 2023 | A cross-site scripting (XSS) vulnerability in Pear-Admin-Boot up to v2.0.2 allows attackers to execute arbitrary web scr... |
| CVE-2023-26843 | MEDIUM | 5.4 | 1.4% | Apr 25, 2023 | A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web scr... |
| CVE-2023-26841 | MEDIUM | 6.5 | 0.4% | Apr 25, 2023 | A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password exc... |
| CVE-2023-26840 | MEDIUM | 5.3 | 0.3% | Apr 25, 2023 | A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set... |
| CVE-2023-26839 | MEDIUM | 4.3 | 0.3% | Apr 25, 2023 | A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to edit information for existing ... |
| CVE-2023-26058 | MEDIUM | 6.5 | 0.5% | Apr 25, 2023 | An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input va... |
| CVE-2023-26057 | MEDIUM | 6.5 | 0.5% | Apr 25, 2023 | An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. In... |
| CVE-2023-25347 | MEDIUM | 5.4 | 0.6% | Apr 25, 2023 | A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web sc... |
| CVE-2023-25346 | MEDIUM | 6.1 | 1.5% | Apr 25, 2023 | A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web ... |
| CVE-2023-27619 | MEDIUM | 5.4 | 0.4% | Apr 25, 2023 | Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes Regina Lite theme <= 2.0.7 version... |
| CVE-2023-25710 | MEDIUM | 4.8 | 0.4% | Apr 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DIGITALBLUE Click to Call or Chat Buttons plugin <= 1.... |
| CVE-2023-25490 | MEDIUM | 4.8 | 0.4% | Apr 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plug... |
| CVE-2023-25479 | MEDIUM | 4.8 | 0.4% | Apr 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versi... |
| CVE-2023-22665 | MEDIUM | 5.4 | 1.3% | Apr 25, 2023 | There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. ... |
| CVE-2023-30414 | MEDIUM | 5.5 | 0.3% | Apr 24, 2023 | Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c. |
| CVE-2023-30410 | MEDIUM | 5.5 | 0.3% | Apr 24, 2023 | Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component ecma_op_function_construct at /o... |
| CVE-2023-30408 | MEDIUM | 5.5 | 0.3% | Apr 24, 2023 | Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry. |
| CVE-2023-30406 | MEDIUM | 5.5 | 0.3% | Apr 24, 2023 | Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property... |
| CVE-2023-30627 | MEDIUM | 5.4 | 1.3% | Apr 24, 2023 | jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to versi... |
| CVE-2023-2250 | MEDIUM | 6.7 | 0.2% | Apr 24, 2023 | A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-... |
| CVE-2023-2019 | MEDIUM | 4.4 | 0.3% | Apr 24, 2023 | A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from... |
| CVE-2023-29469 | MEDIUM | 6.5 | 1.0% | Apr 24, 2023 | An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComp... |
| CVE-2023-28484 | MEDIUM | 6.5 | 1.1% | Apr 24, 2023 | In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently... |
| CVE-2023-29530 | MEDIUM | 6.5 | 1.0% | Apr 24, 2023 | Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now