2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45899HIGH7.5An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attack...
CVE-2023-5867MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
CVE-2023-5866MEDIUM5.7Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.
CVE-2023-5865CRITICAL9.8Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
CVE-2023-5864MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.1.
CVE-2023-5863MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
CVE-2023-5862LOW3.3Missing Authorization in GitHub repository hamza417/inure prior to Build95.
CVE-2023-5861MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-31794MEDIUM5.5MuPDF v1.21.1 was discovered to contain an infinite recursion in the component pdf_mark_list_push. This vulnerability al...
CVE-2023-46139MEDIUM5.7KernelSU is a Kernel based root solution for Android. Starting in version 0.6.1 and prior to version 0.7.0, if a KernelS...
CVE-2023-46138MEDIUM5.3JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Pr...
CVE-2023-46129HIGH7.5NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise,...
CVE-2023-46502CRITICAL9.8An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery atta...
CVE-2023-46478HIGH8.8An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data ...
CVE-2023-45804Rejected reason: User requested a CVE number by mistake
CVE-2023-45672HIGH7.5Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, an unsafe deserialization vulnerabilit...
CVE-2023-45671MEDIUM4.7Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, there is a reflected cross-site script...
CVE-2023-45670MEDIUM6.8Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, the `config/save` and `config/set` end...
CVE-2023-44397CRITICAL9.8CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter ...
CVE-2023-43798MEDIUM5.4BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable t...
CVE-2023-43797MEDIUM5.4BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable...
CVE-2023-45956HIGH7.5An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveW...
CVE-2023-42323HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in DouHaocms v.3.3 allows a remote attacker to execute arbitrary code vi...
CVE-2023-5349LOW3.3A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial ...
CVE-2023-43792CRITICAL9.8baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now