2023 CVE Vulnerabilities

31,400 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45471MEDIUM5.4The QAD Search Server is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to, and including, 1.0.0.315 due...
CVE-2023-45394MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 ...
CVE-2023-5655Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5534. Reason: This record is a reservatio...
CVE-2023-5647Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5212. Reason: This record is a reservatio...
CVE-2023-5646Rejected reason: ** REJECT **DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5241. Reason: This record is a reservatio...
CVE-2023-46115MEDIUM5.5Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerabil...
CVE-2023-41894MEDIUM5.3Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook compone...
CVE-2023-41893MEDIUM5.4Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `clien...
CVE-2023-39731MEDIUM5.3The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send ...
CVE-2023-44385HIGH8.8The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. A...
CVE-2023-43345HIGH8.6Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary co...
CVE-2023-43340MEDIUM5.2Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a cr...
CVE-2023-41899HIGH7.2Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a parti...
CVE-2023-41898HIGH7.8Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is...
CVE-2023-41897CRITICAL9.6Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, includin...
CVE-2023-41896CRITICAL9Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure5...
CVE-2023-41895CRITICAL9.6Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Ass...
CVE-2023-45819MEDIUM6.1TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notif...
CVE-2023-45818MEDIUM6.1TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyM...
CVE-2023-45815MEDIUM5.4ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the...
CVE-2023-45280MEDIUM5.4Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the up...
CVE-2023-45279MEDIUM5.4Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the up...
CVE-2023-44690HIGH7.5Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py
CVE-2023-43875MEDIUM6.1Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to ex...
CVE-2023-43359MEDIUM5.4Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a cra...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now