2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0794 | MEDIUM | 5.4 | 0.6% | Feb 12, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11. |
| CVE-2023-0792 | MEDIUM | 5.4 | 0.6% | Feb 12, 2023 | Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11. |
| CVE-2023-0791 | MEDIUM | 5.4 | 0.6% | Feb 12, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11. |
| CVE-2023-0787 | MEDIUM | 5.4 | 0.5% | Feb 12, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11. |
| CVE-2023-0786 | MEDIUM | 4.8 | 0.6% | Feb 12, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11. |
| CVE-2023-0661 | MEDIUM | 6.5 | 0.7% | Feb 12, 2023 | Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data. |
| CVE-2023-0780 | MEDIUM | 5.4 | 0.4% | Feb 11, 2023 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev. |
| CVE-2023-23161 | MEDIUM | 6.1 | 5.9% | Feb 10, 2023 | A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e... |
| CVE-2023-24234 | MEDIUM | 4.8 | 0.5% | Feb 10, 2023 | A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventor... |
| CVE-2023-24233 | MEDIUM | 4.8 | 0.5% | Feb 10, 2023 | A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/orders.php?o=add of ... |
| CVE-2023-24232 | MEDIUM | 4.8 | 0.5% | Feb 10, 2023 | A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/product.php of Inven... |
| CVE-2023-24231 | MEDIUM | 4.8 | 0.5% | Feb 10, 2023 | A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/categories.php of In... |
| CVE-2023-24230 | MEDIUM | 4.8 | 0.5% | Feb 10, 2023 | A stored cross-site scripting (XSS) vulnerability in the component /formwork/panel/dashboard of Formwork v1.12.1 allows ... |
| CVE-2023-23286 | MEDIUM | 6.1 | 2.6% | Feb 10, 2023 | Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the s... |
| CVE-2023-24690 | MEDIUM | 5.4 | 0.5% | Feb 9, 2023 | ChurchCRM 4.5.3 and below was discovered to contain a stored cross-site scripting (XSS) vulnerability at /api/public/reg... |
| CVE-2023-24686 | MEDIUM | 4.8 | 0.7% | Feb 9, 2023 | An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importi... |
| CVE-2023-24689 | MEDIUM | 4.3 | 0.7% | Feb 9, 2023 | An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of... |
| CVE-2023-24688 | MEDIUM | 5.3 | 0.7% | Feb 9, 2023 | An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registr... |
| CVE-2023-24687 | MEDIUM | 5.4 | 0.6% | Feb 9, 2023 | Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Sett... |
| CVE-2023-24322 | MEDIUM | 6.1 | 31.7% | Feb 9, 2023 | A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows atta... |
| CVE-2023-22798 | MEDIUM | 6.1 | 0.5% | Feb 9, 2023 | Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interc... |
| CVE-2023-22797 | MEDIUM | 6.1 | 0.6% | Feb 9, 2023 | An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling red... |
| CVE-2023-21446 | MEDIUM | 5.5 | 0.2% | Feb 9, 2023 | Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.0... |
| CVE-2023-21442 | MEDIUM | 5.5 | 0.2% | Feb 9, 2023 | Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.0... |
| CVE-2023-21441 | MEDIUM | 5.5 | 0.1% | Feb 9, 2023 | Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now