2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27095 | MEDIUM | 6.5 | 0.6% | Mar 16, 2023 | Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddU... |
| CVE-2023-27084 | MEDIUM | 5.3 | 0.2% | Mar 16, 2023 | Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information... |
| CVE-2023-28487 | MEDIUM | 5.3 | 1.0% | Mar 16, 2023 | Sudo before 1.9.13 does not escape control characters in sudoreplay output. |
| CVE-2023-28486 | MEDIUM | 5.3 | 0.9% | Mar 16, 2023 | Sudo before 1.9.13 does not escape control characters in log messages. |
| CVE-2023-26951 | MEDIUM | 5.4 | 0.3% | Mar 16, 2023 | onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List modul... |
| CVE-2023-1421 | MEDIUM | 6.1 | 0.4% | Mar 15, 2023 | A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker t... |
| CVE-2023-26912 | MEDIUM | 4.8 | 0.4% | Mar 15, 2023 | Cross site scripting (XSS) vulnerability in xenv S-mall-ssm thru commit 3d9e77f7d80289a30f67aaba1ae73e375d33ef71 on Feb ... |
| CVE-2023-25680 | MEDIUM | 6.5 | 0.6% | Mar 15, 2023 | IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Pro... |
| CVE-2023-25282 | MEDIUM | 6.5 | 1.0% | Mar 15, 2023 | A heap overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the config.... |
| CVE-2023-22876 | MEDIUM | 6.5 | 0.5% | Mar 15, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privilege... |
| CVE-2023-25804 | MEDIUM | 5.3 | 0.8% | Mar 15, 2023 | Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a... |
| CVE-2023-1418 | MEDIUM | 6.1 | 0.6% | Mar 15, 2023 | A vulnerability classified as problematic was found in SourceCodester Friendly Island Pizza Website and Ordering System ... |
| CVE-2023-27102 | MEDIUM | 6.5 | 0.7% | Mar 15, 2023 | Libde265 v1.0.11 was discovered to contain a segmentation violation via the function decoder_context::process_slice_segm... |
| CVE-2023-0322 | MEDIUM | 6.1 | 0.4% | Mar 15, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Talent Software UN... |
| CVE-2023-25695 | MEDIUM | 5.3 | 1.4% | Mar 15, 2023 | Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.... |
| CVE-2023-27234 | MEDIUM | 6.5 | 0.3% | Mar 15, 2023 | A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configura... |
| CVE-2023-27589 | MEDIUM | 6.5 | 0.9% | Mar 14, 2023 | Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03... |
| CVE-2023-24923 | MEDIUM | 5.5 | 0.8% | Mar 14, 2023 | Microsoft OneDrive for Android Information Disclosure Vulnerability |
| CVE-2023-24922 | MEDIUM | 6.5 | 1.5% | Mar 14, 2023 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
| CVE-2023-24921 | MEDIUM | 5.4 | 0.6% | Mar 14, 2023 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2023-24920 | MEDIUM | 5.4 | 0.3% | Mar 14, 2023 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2023-24919 | MEDIUM | 5.4 | 0.6% | Mar 14, 2023 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2023-24911 | MEDIUM | 4.3 | 1.1% | Mar 14, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
| CVE-2023-24906 | MEDIUM | 6.5 | 1.5% | Mar 14, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
| CVE-2023-24891 | MEDIUM | 5.4 | 0.6% | Mar 14, 2023 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now