2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0609 | MEDIUM | 4.3 | 0.6% | Feb 1, 2023 | Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3. |
| CVE-2023-0608 | MEDIUM | 5.4 | 0.5% | Feb 1, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2. |
| CVE-2023-0607 | MEDIUM | 4.8 | 0.7% | Feb 1, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository projectsend/projectsend prior to r1606. |
| CVE-2023-23630 | MEDIUM | 6.1 | 0.6% | Feb 1, 2023 | Eta is an embedded JS templating engine that works inside Node, Deno, and the browser. XSS attack - anyone using the Exp... |
| CVE-2023-0606 | MEDIUM | 6.1 | 0.6% | Feb 1, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7. |
| CVE-2023-0593 | MEDIUM | 5.5 | 0.4% | Jan 31, 2023 | A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attac... |
| CVE-2023-0592 | MEDIUM | 5.5 | 0.4% | Jan 31, 2023 | A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attack... |
| CVE-2023-0591 | MEDIUM | 5.5 | 0.4% | Jan 31, 2023 | ubireader_extract_files is vulnerable to path traversal when run against specifically crafted UBIFS files, allowing the... |
| CVE-2023-22389 | MEDIUM | 6.5 | 0.5% | Jan 30, 2023 | Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configura... |
| CVE-2023-0097 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of ... |
| CVE-2023-0074 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before ... |
| CVE-2023-0071 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputti... |
| CVE-2023-0033 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The PDF Viewer WordPress plugin before 1.0.0 does not validate and escape one of its shortcode attributes, which could a... |
| CVE-2023-0581 | MEDIUM | 5.3 | 0.7% | Jan 30, 2023 | The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side valid... |
| CVE-2023-22333 | MEDIUM | 6.1 | 0.5% | Jan 30, 2023 | Cross-site scripting vulnerability in EasyMail 2.00.130 and earlier allows a remote unauthenticated attacker to inject a... |
| CVE-2023-22332 | MEDIUM | 6.5 | 0.7% | Jan 30, 2023 | Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0... |
| CVE-2023-22324 | MEDIUM | 6.5 | 1.3% | Jan 30, 2023 | SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attack... |
| CVE-2023-22322 | MEDIUM | 5.5 | 0.2% | Jan 30, 2023 | Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and ea... |
| CVE-2023-24622 | MEDIUM | 5.3 | 0.6% | Jan 30, 2023 | isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for ex... |
| CVE-2023-0572 | MEDIUM | 5.3 | 0.7% | Jan 29, 2023 | Unchecked Error Condition in GitHub repository froxlor/froxlor prior to 2.0.10. |
| CVE-2023-24065 | MEDIUM | 5.4 | 0.6% | Jan 29, 2023 | NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billin... |
| CVE-2023-0566 | MEDIUM | 4.8 | 0.4% | Jan 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlor prior to 2.0.10.... |
| CVE-2023-0565 | MEDIUM | 4.9 | 0.6% | Jan 29, 2023 | Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.10. |
| CVE-2023-0571 | MEDIUM | 5.4 | 0.6% | Jan 29, 2023 | A vulnerability has been found in SourceCodester Canteen Management System 1.0 and classified as problematic. This vulne... |
| CVE-2023-0569 | MEDIUM | 6.5 | 0.7% | Jan 29, 2023 | Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now