2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1586 | MEDIUM | 4.7 | 0.2% | Apr 19, 2023 | Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the resto... |
| CVE-2023-1585 | MEDIUM | 6.3 | 0.2% | Apr 19, 2023 | Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the Quara... |
| CVE-2023-30614 | MEDIUM | 6.1 | 0.4% | Apr 19, 2023 | Pay is a payments engine for Ruby on Rails 6.0 and higher. In versions prior to 6.3.2 a payments info page of Pay is sus... |
| CVE-2023-30612 | MEDIUM | 4.9 | 0.4% | Apr 19, 2023 | Cloud hypervisor is a Virtual Machine Monitor for Cloud workloads. This vulnerability allows users to close arbitrary op... |
| CVE-2023-30611 | MEDIUM | 5.3 | 0.4% | Apr 19, 2023 | Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform.... |
| CVE-2023-30610 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` stru... |
| CVE-2023-22894 | MEDIUM | 4.9 | 1.7% | Apr 19, 2023 | Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting ... |
| CVE-2023-29586 | MEDIUM | 5.5 | 0.3% | Apr 19, 2023 | Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This ... |
| CVE-2023-29923 | MEDIUM | 5.3 | 9.5% | Apr 19, 2023 | PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface. |
| CVE-2023-27777 | MEDIUM | 5.4 | 0.4% | Apr 19, 2023 | Cross-site scripting (XSS) vulnerability was discovered in Online Jewelry Shop v1.0 that allows attackers to execute arb... |
| CVE-2023-29921 | MEDIUM | 5.3 | 0.5% | Apr 19, 2023 | PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create app interface. |
| CVE-2023-27776 | MEDIUM | 5.4 | 0.5% | Apr 19, 2023 | A stored cross-site scripting (XSS) vulnerability in /index.php?page=category_list of Online Jewelry Shop v1.0 allows at... |
| CVE-2023-26599 | MEDIUM | 6.1 | 0.4% | Apr 19, 2023 | XSS vulnerability in TripleSign in Tripleplay Platform releases prior to Caveman 3.4.0 allows attackers to inject client... |
| CVE-2023-25759 | MEDIUM | 5.4 | 0.9% | Apr 19, 2023 | OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authen... |
| CVE-2023-0317 | MEDIUM | 4.9 | 0.5% | Apr 19, 2023 | Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensi... |
| CVE-2023-2170 | MEDIUM | 4.8 | 0.5% | Apr 19, 2023 | The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in v... |
| CVE-2023-2169 | MEDIUM | 4.8 | 0.5% | Apr 19, 2023 | The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in v... |
| CVE-2023-2168 | MEDIUM | 4.8 | 0.5% | Apr 19, 2023 | The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in ver... |
| CVE-2023-25620 | MEDIUM | 6.5 | 0.6% | Apr 19, 2023 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of servi... |
| CVE-2023-30605 | MEDIUM | 6.5 | 0.8% | Apr 19, 2023 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ... |
| CVE-2023-30558 | MEDIUM | 6.5 | 0.8% | Apr 19, 2023 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ... |
| CVE-2023-30557 | MEDIUM | 6.5 | 0.8% | Apr 19, 2023 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ... |
| CVE-2023-30556 | MEDIUM | 6.5 | 0.8% | Apr 19, 2023 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ... |
| CVE-2023-30555 | MEDIUM | 6.5 | 0.8% | Apr 19, 2023 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ... |
| CVE-2023-30554 | MEDIUM | 6.5 | 0.8% | Apr 19, 2023 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now