2023 CVE Vulnerabilities
31,400 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26570 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier a... |
| CVE-2023-26569 | CRITICAL | 9.1 | 0.8% | Oct 25, 2023 | Unauthenticated SQL injection in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and ea... |
| CVE-2023-26568 | CRITICAL | 9.1 | 0.8% | Oct 25, 2023 | Unauthenticated SQL injection in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier ... |
| CVE-2023-26219 | HIGH | 8.8 | 0.4% | Oct 25, 2023 | The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver... |
| CVE-2023-25032 | MEDIUM | 4.8 | 0.4% | Oct 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Print, PDF, Email by PrintFriendly plugin <= 5.5.1 ver... |
| CVE-2023-23767 | — | — | — | Oct 25, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by GitHub as it was issued in error. |
| CVE-2023-20273 | HIGH | 7.2 | 89.6% | Oct 25, 2023 | A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c... |
| CVE-2023-1356 | MEDIUM | 6.1 | 0.4% | Oct 25, 2023 | Reflected cross-site scripting in the StudentSearch component in IDAttend’s IDWeb application 3.1.052 and earlier allows... |
| CVE-2023-46059 | MEDIUM | 4.8 | 0.6% | Oct 24, 2023 | Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary c... |
| CVE-2023-46058 | MEDIUM | 4.8 | 0.6% | Oct 24, 2023 | Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary c... |
| CVE-2023-33517 | HIGH | 7.5 | 0.7% | Oct 23, 2023 | carRental 1.0 is vulnerable to Incorrect Access Control (Arbitrary File Read on the Back-end System). |
| CVE-2023-5633 | HIGH | 7.8 | 0.3% | Oct 23, 2023 | The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in... |
| CVE-2023-45998 | MEDIUM | 5.4 | 0.3% | Oct 23, 2023 | kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS. |
| CVE-2023-44760 | MEDIUM | 4.8 | 0.6% | Oct 23, 2023 | Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code ... |
| CVE-2023-43358 | MEDIUM | 5.4 | 0.5% | Oct 23, 2023 | Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a cra... |
| CVE-2023-45966 | HIGH | 7.5 | 0.6% | Oct 23, 2023 | umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability. |
| CVE-2023-37636 | MEDIUM | 5.4 | 0.3% | Oct 23, 2023 | A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitr... |
| CVE-2023-37635 | CRITICAL | 9.8 | 1.2% | Oct 23, 2023 | UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to ga... |
| CVE-2023-27152 | CRITICAL | 9.8 | 0.9% | Oct 23, 2023 | DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack ... |
| CVE-2023-46603 | HIGH | 8.8 | 0.5% | Oct 23, 2023 | In International Color Consortium DemoIccMAX 79ecb74, there is an out-of-bounds read in the CIccPRMG::GetChroma function... |
| CVE-2023-46602 | HIGH | 8.8 | 0.5% | Oct 23, 2023 | In International Color Consortium DemoIccMAX 79ecb74, there is a stack-based buffer overflow in the icFixXml function in... |
| CVE-2023-33840 | MEDIUM | 4.8 | 0.3% | Oct 23, 2023 | IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2023-33839 | HIGH | 8.8 | 1.1% | Oct 23, 2023 | IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the sys... |
| CVE-2023-33837 | HIGH | 7.5 | 0.3% | Oct 23, 2023 | IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. ... |
| CVE-2023-27149 | MEDIUM | 4.8 | 0.4% | Oct 23, 2023 | A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now