2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26454 | HIGH | 8.8 | 0.4% | Nov 2, 2023 | Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked. Exploiting thi... |
| CVE-2023-26453 | HIGH | 8.8 | 0.4% | Nov 2, 2023 | Requests to cache an image could be abused to include SQL queries that would be executed unchecked. Exploiting this vuln... |
| CVE-2023-26452 | HIGH | 8.8 | 0.4% | Nov 2, 2023 | Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed uncheck... |
| CVE-2023-46475 | MEDIUM | 5.4 | 0.4% | Nov 2, 2023 | A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the ... |
| CVE-2023-5918 | CRITICAL | 9.8 | 0.7% | Nov 2, 2023 | A vulnerability, which was classified as critical, was found in SourceCodester Visitor Management System 1.0. Affected i... |
| CVE-2023-5860 | HIGH | 7.2 | 1.0% | Nov 2, 2023 | The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i... |
| CVE-2023-43336 | HIGH | 8.8 | 0.8% | Nov 2, 2023 | Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access contr... |
| CVE-2023-43193 | MEDIUM | 6.1 | 0.5% | Nov 2, 2023 | Submitty before v22.06.00 is vulnerable to Cross Site Scripting (XSS). An attacker can create a malicious link in the fo... |
| CVE-2023-3164 | MEDIUM | 5.5 | 0.3% | Nov 2, 2023 | A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/t... |
| CVE-2023-5917 | MEDIUM | 6.1 | 0.5% | Nov 2, 2023 | A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the funct... |
| CVE-2023-5916 | MEDIUM | 4.3 | 0.5% | Nov 2, 2023 | A vulnerability classified as critical has been found in Lissy93 Dashy 2.1.1. This affects an unknown part of the file /... |
| CVE-2023-43087 | MEDIUM | 6.5 | 0.4% | Nov 2, 2023 | Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privilege... |
| CVE-2023-43076 | MEDIUM | 6.5 | 0.6% | Nov 2, 2023 | Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker... |
| CVE-2023-5920 | LOW | 3.3 | 0.2% | Nov 2, 2023 | Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for ot... |
| CVE-2023-5876 | MEDIUM | 5.3 | 0.5% | Nov 2, 2023 | Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enro... |
| CVE-2023-5875 | MEDIUM | 5.3 | 0.3% | Nov 2, 2023 | Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowi... |
| CVE-2023-5606 | MEDIUM | 4.8 | 0.3% | Nov 2, 2023 | The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9... |
| CVE-2023-46595 | MEDIUM | 5.4 | 0.3% | Nov 2, 2023 | Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain cre... |
| CVE-2023-47204 | CRITICAL | 9.8 | 0.8% | Nov 2, 2023 | Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python ... |
| CVE-2023-46695 | HIGH | 7.5 | 49.8% | Nov 2, 2023 | An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is ... |
| CVE-2023-5408 | HIGH | 7.2 | 1.1% | Nov 2, 2023 | A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift... |
| CVE-2023-46327 | MEDIUM | 5.9 | 0.4% | Nov 2, 2023 | Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a fa... |
| CVE-2023-45019 | CRITICAL | 9.8 | 0.7% | Nov 2, 2023 | Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'category' p... |
| CVE-2023-45018 | CRITICAL | 9.8 | 0.7% | Nov 2, 2023 | Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' p... |
| CVE-2023-45017 | — | — | — | Nov 2, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now