2023 CVE Vulnerabilities

31,400 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26570HIGH7.5Missing authentication in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier a...
CVE-2023-26569CRITICAL9.1Unauthenticated SQL injection in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and ea...
CVE-2023-26568CRITICAL9.1Unauthenticated SQL injection in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier ...
CVE-2023-26219HIGH8.8The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver...
CVE-2023-25032MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Print, PDF, Email by PrintFriendly plugin <= 5.5.1 ver...
CVE-2023-23767Rejected reason: This CVE ID has been rejected or withdrawn by GitHub as it was issued in error.
CVE-2023-20273HIGH7.2A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c...
CVE-2023-1356MEDIUM6.1Reflected cross-site scripting in the StudentSearch component in IDAttend’s IDWeb application 3.1.052 and earlier allows...
CVE-2023-46059MEDIUM4.8Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary c...
CVE-2023-46058MEDIUM4.8Cross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary c...
CVE-2023-33517HIGH7.5carRental 1.0 is vulnerable to Incorrect Access Control (Arbitrary File Read on the Back-end System).
CVE-2023-5633HIGH7.8The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in...
CVE-2023-45998MEDIUM5.4kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS.
CVE-2023-44760MEDIUM4.8Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code ...
CVE-2023-43358MEDIUM5.4Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a cra...
CVE-2023-45966HIGH7.5umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability.
CVE-2023-37636MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitr...
CVE-2023-37635CRITICAL9.8UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to ga...
CVE-2023-27152CRITICAL9.8DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack ...
CVE-2023-46603HIGH8.8In International Color Consortium DemoIccMAX 79ecb74, there is an out-of-bounds read in the CIccPRMG::GetChroma function...
CVE-2023-46602HIGH8.8In International Color Consortium DemoIccMAX 79ecb74, there is a stack-based buffer overflow in the icFixXml function in...
CVE-2023-33840MEDIUM4.8IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2023-33839HIGH8.8IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the sys...
CVE-2023-33837HIGH7.5IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. ...
CVE-2023-27149MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now