2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0062 | MEDIUM | 5.4 | 0.6% | Feb 6, 2023 | The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes befo... |
| CVE-2023-24197 | MEDIUM | 6.1 | 0.5% | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_orde... |
| CVE-2023-24195 | MEDIUM | 6.1 | 0.5% | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page paramet... |
| CVE-2023-24194 | MEDIUM | 6.1 | 0.5% | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page paramet... |
| CVE-2023-24192 | MEDIUM | 6.1 | 0.5% | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect par... |
| CVE-2023-24191 | MEDIUM | 6.1 | 0.5% | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect par... |
| CVE-2023-22849 | MEDIUM | 6.1 | 1.4% | Feb 4, 2023 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling ... |
| CVE-2023-0678 | MEDIUM | 5.3 | 37.3% | Feb 4, 2023 | Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1. |
| CVE-2023-0677 | MEDIUM | 6.1 | 0.4% | Feb 4, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1. |
| CVE-2023-0676 | MEDIUM | 6.1 | 1.5% | Feb 4, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1. |
| CVE-2023-0674 | MEDIUM | 6.5 | 0.4% | Feb 4, 2023 | A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some un... |
| CVE-2023-23615 | MEDIUM | 5.3 | 0.5% | Feb 3, 2023 | Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any us... |
| CVE-2023-23082 | MEDIUM | 4.6 | 0.7% | Feb 3, 2023 | A heap buffer overflow vulnerability in Kodi Home Theater Software up to 19.5 allows attackers to cause a denial of serv... |
| CVE-2023-23940 | MEDIUM | 5.3 | 0.2% | Feb 3, 2023 | OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a dec... |
| CVE-2023-23937 | MEDIUM | 5.4 | 0.5% | Feb 3, 2023 | Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. The upl... |
| CVE-2023-23933 | MEDIUM | 4.3 | 0.5% | Feb 3, 2023 | OpenSearch Anomaly Detection identifies atypical data and receives automatic notifications. There is an issue with the a... |
| CVE-2023-22975 | MEDIUM | 6.1 | 0.4% | Feb 3, 2023 | A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTM... |
| CVE-2023-25136 | MEDIUM | 6.5 | 90.0% | Feb 3, 2023 | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed i... |
| CVE-2023-24613 | MEDIUM | 4.9 | 0.8% | Feb 3, 2023 | The user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb t... |
| CVE-2023-23636 | MEDIUM | 5.4 | 0.6% | Feb 3, 2023 | In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal ... |
| CVE-2023-23635 | MEDIUM | 5.4 | 0.6% | Feb 3, 2023 | In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to stea... |
| CVE-2023-23120 | MEDIUM | 5.9 | 0.3% | Feb 2, 2023 | The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP65... |
| CVE-2023-23119 | MEDIUM | 5.9 | 0.3% | Feb 2, 2023 | The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes Ubiquiti airFibe... |
| CVE-2023-0650 | MEDIUM | 5.4 | 0.7% | Feb 2, 2023 | A vulnerability was found in YAFNET up to 3.1.11 and classified as problematic. This issue affects some unknown processi... |
| CVE-2023-0643 | MEDIUM | 6.1 | 0.6% | Feb 2, 2023 | Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now