2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23949 | MEDIUM | 5.4 | 0.6% | Jan 26, 2023 | An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser. |
| CVE-2023-23613 | MEDIUM | 6.5 | 0.8% | Jan 26, 2023 | OpenSearch is an open source distributed and RESTful search engine. In affected versions there is an issue in the implem... |
| CVE-2023-23611 | MEDIUM | 5.4 | 0.4% | Jan 26, 2023 | LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provid... |
| CVE-2023-23610 | MEDIUM | 6.5 | 0.7% | Jan 26, 2023 | GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper ... |
| CVE-2023-23608 | MEDIUM | 4.3 | 0.7% | Jan 26, 2023 | Spotipy is a light weight Python library for the Spotify Web API. In versions prior to 2.22.1, if a malicious URI is pas... |
| CVE-2023-23151 | MEDIUM | 6.5 | 1.0% | Jan 26, 2023 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_co... |
| CVE-2023-22971 | MEDIUM | 6.1 | 0.7% | Jan 26, 2023 | Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, ... |
| CVE-2023-22739 | MEDIUM | 6.5 | 0.9% | Jan 26, 2023 | Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and... |
| CVE-2023-22725 | MEDIUM | 4.8 | 0.6% | Jan 26, 2023 | GLPI is a Free Asset and IT Management Software package. Versions 0.6.0 and above, prior to 10.0.6 are vulnerable to Cro... |
| CVE-2023-22724 | MEDIUM | 4.8 | 0.6% | Jan 26, 2023 | GLPI is a Free Asset and IT Management Software package. Versions prior to 10.0.6 are subject to Cross-site Scripting vi... |
| CVE-2023-22722 | MEDIUM | 6.1 | 0.6% | Jan 26, 2023 | GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-... |
| CVE-2023-22468 | MEDIUM | 5.4 | 0.5% | Jan 26, 2023 | Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) an... |
| CVE-2023-20924 | MEDIUM | 6.8 | 0.2% | Jan 26, 2023 | In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to lo... |
| CVE-2023-20923 | MEDIUM | 5.5 | 0.1% | Jan 26, 2023 | In exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to... |
| CVE-2023-20922 | MEDIUM | 5.5 | 0.1% | Jan 26, 2023 | In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lea... |
| CVE-2023-20908 | MEDIUM | 5.5 | 0.1% | Jan 26, 2023 | In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could... |
| CVE-2023-0513 | MEDIUM | 5.4 | 0.7% | Jan 26, 2023 | A vulnerability has been found in isoftforce Dreamer CMS up to 4.0.1 and classified as problematic. This vulnerability a... |
| CVE-2023-0476 | MEDIUM | 6.5 | 0.7% | Jan 26, 2023 | A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning i... |
| CVE-2023-0469 | MEDIUM | 5.5 | 0.3% | Jan 26, 2023 | A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Lin... |
| CVE-2023-0468 | MEDIUM | 4.7 | 0.3% | Jan 26, 2023 | A use-after-free flaw was found in io_uring/poll.c in io_poll_check_events in the io_uring subcomponent in the Linux Ker... |
| CVE-2023-0452 | MEDIUM | 5.3 | 0.5% | Jan 26, 2023 | Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configura... |
| CVE-2023-0448 | MEDIUM | 6.1 | 44.5% | Jan 26, 2023 | The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resultin... |
| CVE-2023-0417 | MEDIUM | 6.5 | 0.9% | Jan 26, 2023 | Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet... |
| CVE-2023-0416 | MEDIUM | 6.5 | 0.9% | Jan 26, 2023 | GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or... |
| CVE-2023-0415 | MEDIUM | 6.5 | 0.9% | Jan 26, 2023 | iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now