2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25621 | MEDIUM | 6.5 | 1.1% | Feb 23, 2023 | Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n... |
| CVE-2023-26303 | MEDIUM | 5.5 | 0.2% | Feb 23, 2023 | Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions ... |
| CVE-2023-26302 | MEDIUM | 5.5 | 0.2% | Feb 22, 2023 | Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was all... |
| CVE-2023-22972 | MEDIUM | 5.4 | 0.4% | Feb 22, 2023 | A Reflected Cross-site scripting (XSS) vulnerability in interface/forms/eye_mag/php/eye_mag_functions.php in OpenEMR < 7... |
| CVE-2023-24811 | MEDIUM | 6.1 | 0.4% | Feb 22, 2023 | Misskey is an open source, decentralized social media platform. In versions prior to 13.3.2 the URL preview function is ... |
| CVE-2023-24810 | MEDIUM | 6.1 | 0.4% | Feb 22, 2023 | Misskey is an open source, decentralized social media platform. Due to insufficient validation of the redirect URL durin... |
| CVE-2023-25154 | MEDIUM | 6.1 | 0.4% | Feb 22, 2023 | Misskey is an open source, decentralized social media platform. In versions prior to 13.5.0 the link to the instance to ... |
| CVE-2023-0846 | MEDIUM | 6.1 | 0.5% | Feb 22, 2023 | Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Hori... |
| CVE-2023-26214 | MEDIUM | 5.4 | 0.4% | Feb 22, 2023 | The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains easily exploitable Reflected Cr... |
| CVE-2023-23039 | MEDIUM | 5.7 | 0.2% | Feb 22, 2023 | An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-... |
| CVE-2023-0949 | MEDIUM | 4.8 | 0.5% | Feb 22, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository modoboa/modoboa prior to 2.0.5. |
| CVE-2023-24081 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | Multiple stored cross-site scripting (XSS) vulnerabilities in Redrock Software TutorTrac before v4.2.170210 allows attac... |
| CVE-2023-25811 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma `name` parameter allows a pers... |
| CVE-2023-25810 | MEDIUM | 5.4 | 0.4% | Feb 21, 2023 | Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma status page allows a persisten... |
| CVE-2023-0945 | MEDIUM | 5.4 | 0.4% | Feb 21, 2023 | A vulnerability, which was classified as problematic, was found in SourceCodester Best POS Management System 1.0. Affect... |
| CVE-2023-0942 | MEDIUM | 6.1 | 1.2% | Feb 21, 2023 | The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ paramet... |
| CVE-2023-23009 | MEDIUM | 6.5 | 1.6% | Feb 21, 2023 | Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS pa... |
| CVE-2023-22984 | MEDIUM | 6.1 | 0.5% | Feb 21, 2023 | A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administra... |
| CVE-2023-0934 | MEDIUM | 5.4 | 0.4% | Feb 21, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.5. |
| CVE-2023-25928 | MEDIUM | 5.4 | 0.4% | Feb 21, 2023 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2023-0936 | MEDIUM | 6.5 | 0.9% | Feb 21, 2023 | A vulnerability was found in TP-Link Archer C50 V2_160801. It has been rated as problematic. Affected by this issue is s... |
| CVE-2023-26267 | MEDIUM | 6.5 | 0.5% | Feb 21, 2023 | php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML... |
| CVE-2023-0559 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The GS Portfolio for Envato WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes ... |
| CVE-2023-0541 | MEDIUM | 5.4 | 0.6% | Feb 21, 2023 | The GS Books Showcase WordPress plugin before 1.3.1 does not validate and escape some of its shortcode attributes before... |
| CVE-2023-0540 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The GS Filterable Portfolio WordPress plugin before 1.6.1 does not validate and escape some of its shortcode attributes ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now