2023 CVE Vulnerabilities
31,250 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1752 | MEDIUM | 4.3 | 0.5% | Apr 4, 2023 | The listed versions of Nexx Smart Home devices could allow any user to register an already registered alarm or associate... |
| CVE-2023-1751 | MEDIUM | 5.3 | 0.6% | Apr 4, 2023 | The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the ... |
| CVE-2023-1749 | MEDIUM | 6.5 | 0.5% | Apr 4, 2023 | The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a val... |
| CVE-2023-26974 | MEDIUM | 5.5 | 0.6% | Apr 4, 2023 | Irfanview v4.62 allows a user-mode write access violation via a crafted JPEG 2000 file starting at JPEG2000+0x0000000000... |
| CVE-2023-27734 | MEDIUM | 5.5 | 0.2% | Apr 4, 2023 | An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbol... |
| CVE-2023-26777 | MEDIUM | 6.1 | 0.7% | Apr 4, 2023 | Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execu... |
| CVE-2023-26776 | MEDIUM | 6.1 | 1.2% | Apr 4, 2023 | Cross Site Scripting vulnerability found in Monitorr v.1.7.6 allows a remote attacker to execute arbitrary code via the ... |
| CVE-2023-26437 | MEDIUM | 5.3 | 0.6% | Apr 4, 2023 | Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue af... |
| CVE-2023-29000 | MEDIUM | 6.5 | 0.4% | Apr 4, 2023 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior... |
| CVE-2023-28999 | MEDIUM | 6.4 | 0.7% | Apr 4, 2023 | Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app ... |
| CVE-2023-28998 | MEDIUM | 6.1 | 0.7% | Apr 4, 2023 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior... |
| CVE-2023-28997 | MEDIUM | 6.5 | 1.1% | Apr 4, 2023 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior... |
| CVE-2023-28848 | MEDIUM | 5.4 | 0.3% | Apr 4, 2023 | user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in vers... |
| CVE-2023-23977 | MEDIUM | 5.4 | 0.4% | Apr 4, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin fo... |
| CVE-2023-23870 | MEDIUM | 4.8 | 0.4% | Apr 4, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8... |
| CVE-2023-23878 | MEDIUM | 5.4 | 0.4% | Apr 4, 2023 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAP... |
| CVE-2023-23821 | MEDIUM | 4.8 | 0.4% | Apr 4, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcin Pietrzak Interactive Polish Map plugin <= 1.2 v... |
| CVE-2023-23686 | MEDIUM | 5.4 | 0.4% | Apr 4, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brett Shumaker Simple Staff List plugin <= 2.2.2... |
| CVE-2023-23685 | MEDIUM | 5.4 | 0.4% | Apr 4, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in RadiusTheme Portfolio – WordPress Portfolio plug... |
| CVE-2023-25942 | MEDIUM | 6.5 | 0.6% | Apr 4, 2023 | Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious netw... |
| CVE-2023-1768 | MEDIUM | 5.3 | 0.9% | Apr 4, 2023 | Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk... |
| CVE-2023-0922 | MEDIUM | 5.9 | 0.5% | Apr 3, 2023 | The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset pass... |
| CVE-2023-0614 | MEDIUM | 6.5 | 0.6% | Apr 3, 2023 | The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insuf... |
| CVE-2023-0225 | MEDIUM | 4.3 | 0.7% | Apr 3, 2023 | A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged use... |
| CVE-2023-26916 | MEDIUM | 5.3 | 1.0% | Apr 3, 2023 | libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now