2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45899 | HIGH | 7.5 | 0.8% | Oct 31, 2023 | An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attack... |
| CVE-2023-5867 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.2. |
| CVE-2023-5866 | MEDIUM | 5.7 | 0.3% | Oct 31, 2023 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1. |
| CVE-2023-5865 | CRITICAL | 9.8 | 0.6% | Oct 31, 2023 | Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2. |
| CVE-2023-5864 | MEDIUM | 4.8 | 0.5% | Oct 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.1. |
| CVE-2023-5863 | MEDIUM | 6.1 | 1.1% | Oct 31, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.2. |
| CVE-2023-5862 | LOW | 3.3 | 0.3% | Oct 31, 2023 | Missing Authorization in GitHub repository hamza417/inure prior to Build95. |
| CVE-2023-5861 | MEDIUM | 4.8 | 0.4% | Oct 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0. |
| CVE-2023-31794 | MEDIUM | 5.5 | 0.2% | Oct 31, 2023 | MuPDF v1.21.1 was discovered to contain an infinite recursion in the component pdf_mark_list_push. This vulnerability al... |
| CVE-2023-46139 | MEDIUM | 5.7 | 0.2% | Oct 31, 2023 | KernelSU is a Kernel based root solution for Android. Starting in version 0.6.1 and prior to version 0.7.0, if a KernelS... |
| CVE-2023-46138 | MEDIUM | 5.3 | 0.3% | Oct 31, 2023 | JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Pr... |
| CVE-2023-46129 | HIGH | 7.5 | 0.4% | Oct 31, 2023 | NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise,... |
| CVE-2023-46502 | CRITICAL | 9.8 | 0.7% | Oct 30, 2023 | An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery atta... |
| CVE-2023-46478 | HIGH | 8.8 | 1.0% | Oct 30, 2023 | An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data ... |
| CVE-2023-45804 | — | — | — | Oct 30, 2023 | Rejected reason: User requested a CVE number by mistake |
| CVE-2023-45672 | HIGH | 7.5 | 1.4% | Oct 30, 2023 | Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, an unsafe deserialization vulnerabilit... |
| CVE-2023-45671 | MEDIUM | 4.7 | 1.4% | Oct 30, 2023 | Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, there is a reflected cross-site script... |
| CVE-2023-45670 | MEDIUM | 6.8 | 0.4% | Oct 30, 2023 | Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, the `config/save` and `config/set` end... |
| CVE-2023-44397 | CRITICAL | 9.8 | 0.6% | Oct 30, 2023 | CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter ... |
| CVE-2023-43798 | MEDIUM | 5.4 | 0.4% | Oct 30, 2023 | BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable t... |
| CVE-2023-43797 | MEDIUM | 5.4 | 0.4% | Oct 30, 2023 | BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable... |
| CVE-2023-45956 | HIGH | 7.5 | 0.5% | Oct 30, 2023 | An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveW... |
| CVE-2023-42323 | HIGH | 8.8 | 0.4% | Oct 30, 2023 | Cross Site Request Forgery (CSRF) vulnerability in DouHaocms v.3.3 allows a remote attacker to execute arbitrary code vi... |
| CVE-2023-5349 | LOW | 3.3 | 0.7% | Oct 30, 2023 | A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial ... |
| CVE-2023-43792 | CRITICAL | 9.8 | 0.6% | Oct 30, 2023 | baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now