2023 CVE Vulnerabilities
31,250 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26116 | MEDIUM | 5.3 | 1.7% | Mar 30, 2023 | Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angul... |
| CVE-2023-25000 | MEDIUM | 4.7 | 0.2% | Mar 30, 2023 | HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-... |
| CVE-2023-0665 | MEDIUM | 6.5 | 0.3% | Mar 30, 2023 | HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer met... |
| CVE-2023-0620 | MEDIUM | 6.7 | 0.4% | Mar 30, 2023 | HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when config... |
| CVE-2023-22705 | MEDIUM | 6.1 | 0.4% | Mar 29, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Collne Inc. Welcart e-Commerce plugin <= 2.8.10 versions. |
| CVE-2023-27489 | MEDIUM | 5.4 | 0.5% | Mar 29, 2023 | Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS accepts SVG files up... |
| CVE-2023-25809 | MEDIUM | 6.3 | 0.3% | Mar 29, 2023 | runc is a CLI tool for spawning and running containers according to the OCI specification. In affected versions it was f... |
| CVE-2023-27167 | MEDIUM | 6.5 | 7.5% | Mar 29, 2023 | Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/abs... |
| CVE-2023-26292 | MEDIUM | 6.1 | 0.4% | Mar 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud S... |
| CVE-2023-26291 | MEDIUM | 6.1 | 0.4% | Mar 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud S... |
| CVE-2023-26290 | MEDIUM | 6.1 | 0.4% | Mar 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud S... |
| CVE-2023-1550 | MEDIUM | 5.5 | 0.2% | Mar 29, 2023 | Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 ins... |
| CVE-2023-1704 | MEDIUM | 5.4 | 0.4% | Mar 29, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20. |
| CVE-2023-1703 | MEDIUM | 5.4 | 0.5% | Mar 29, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20. |
| CVE-2023-1702 | MEDIUM | 5.4 | 0.4% | Mar 29, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20. |
| CVE-2023-1701 | MEDIUM | 5.4 | 0.4% | Mar 29, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.20. |
| CVE-2023-26982 | MEDIUM | 5.4 | 1.0% | Mar 29, 2023 | Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter un... |
| CVE-2023-1575 | MEDIUM | 4.8 | 0.4% | Mar 29, 2023 | The Mega Main Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters... |
| CVE-2023-1663 | MEDIUM | 5.3 | 0.4% | Mar 29, 2023 | Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthor... |
| CVE-2023-28158 | MEDIUM | 5.4 | 1.2% | Mar 29, 2023 | Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploite... |
| CVE-2023-1690 | MEDIUM | 6.1 | 0.4% | Mar 29, 2023 | A vulnerability, which was classified as problematic, has been found in SourceCodester Earnings and Expense Tracker App ... |
| CVE-2023-1689 | MEDIUM | 6.1 | 0.4% | Mar 29, 2023 | A vulnerability classified as problematic was found in SourceCodester Earnings and Expense Tracker App 1.0. This vulnera... |
| CVE-2023-1688 | MEDIUM | 6.1 | 0.4% | Mar 29, 2023 | A vulnerability classified as problematic has been found in SourceCodester Earnings and Expense Tracker App 1.0. This af... |
| CVE-2023-1687 | MEDIUM | 6.1 | 0.4% | Mar 29, 2023 | A vulnerability classified as problematic has been found in SourceCodester Simple Task Allocation System 1.0. Affected i... |
| CVE-2023-1686 | MEDIUM | 6.1 | 0.5% | Mar 29, 2023 | A vulnerability was found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. It has been rated as problematic. T... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now