2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23024 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index... |
| CVE-2023-23015 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | Cross Site Scripting (XSS) vulnerability in Kalkun 0.8.0 via username input in file User_model.php. |
| CVE-2023-23014 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr... |
| CVE-2023-23012 | MEDIUM | 6.1 | 0.5% | Jan 20, 2023 | Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary co... |
| CVE-2023-23010 | MEDIUM | 6.1 | 0.6% | Jan 20, 2023 | Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c... |
| CVE-2023-22458 | MEDIUM | 5.5 | 69.4% | Jan 20, 2023 | Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` comm... |
| CVE-2023-22912 | MEDIUM | 5.3 | 0.4% | Jan 20, 2023 | An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. Check... |
| CVE-2023-22910 | MEDIUM | 5.4 | 0.5% | Jan 20, 2023 | An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There... |
| CVE-2023-20058 | MEDIUM | 6.1 | 0.5% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticate... |
| CVE-2023-20057 | MEDIUM | 5.3 | 0.7% | Jan 20, 2023 | A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could ... |
| CVE-2023-20047 | MEDIUM | 6.5 | 0.3% | Jan 20, 2023 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devi... |
| CVE-2023-20043 | MEDIUM | 6.7 | 0.2% | Jan 20, 2023 | A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. ... |
| CVE-2023-20040 | MEDIUM | 5.5 | 1.2% | Jan 20, 2023 | A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote... |
| CVE-2023-20037 | MEDIUM | 5.4 | 0.4% | Jan 20, 2023 | A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cro... |
| CVE-2023-20019 | MEDIUM | 6.1 | 0.6% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWork... |
| CVE-2023-20018 | MEDIUM | 6.5 | 0.6% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unaut... |
| CVE-2023-20002 | MEDIUM | 4.4 | 0.2% | Jan 20, 2023 | A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass acce... |
| CVE-2023-22373 | MEDIUM | 5.4 | 1.9% | Jan 20, 2023 | Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated att... |
| CVE-2023-22334 | MEDIUM | 5.3 | 0.9% | Jan 20, 2023 | Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and ea... |
| CVE-2023-0410 | MEDIUM | 6.1 | 0.5% | Jan 20, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository builderio/qwik prior to 0.1.0-beta5. |
| CVE-2023-22745 | MEDIUM | 6.4 | 0.5% | Jan 19, 2023 | tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 ... |
| CVE-2023-0406 | MEDIUM | 4.3 | 0.4% | Jan 19, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4. |
| CVE-2023-0404 | MEDIUM | 5.4 | 0.5% | Jan 19, 2023 | The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev... |
| CVE-2023-0403 | MEDIUM | 5.4 | 0.4% | Jan 19, 2023 | The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.... |
| CVE-2023-0402 | MEDIUM | 5.4 | 0.8% | Jan 19, 2023 | The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sever... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now