2023 CVE Vulnerabilities
31,400 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45471 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The QAD Search Server is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to, and including, 1.0.0.315 due... |
| CVE-2023-45394 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 ... |
| CVE-2023-5655 | — | — | — | Oct 20, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5534. Reason: This record is a reservatio... |
| CVE-2023-5647 | — | — | — | Oct 20, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5212. Reason: This record is a reservatio... |
| CVE-2023-5646 | — | — | — | Oct 20, 2023 | Rejected reason: ** REJECT **DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5241. Reason: This record is a reservatio... |
| CVE-2023-46115 | MEDIUM | 5.5 | 0.2% | Oct 20, 2023 | Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerabil... |
| CVE-2023-41894 | MEDIUM | 5.3 | 0.4% | Oct 20, 2023 | Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook compone... |
| CVE-2023-41893 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `clien... |
| CVE-2023-39731 | MEDIUM | 5.3 | 0.4% | Oct 20, 2023 | The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send ... |
| CVE-2023-44385 | HIGH | 8.8 | 0.3% | Oct 19, 2023 | The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. A... |
| CVE-2023-43345 | HIGH | 8.6 | 0.4% | Oct 19, 2023 | Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary co... |
| CVE-2023-43340 | MEDIUM | 5.2 | 0.5% | Oct 19, 2023 | Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a cr... |
| CVE-2023-41899 | HIGH | 7.2 | 0.5% | Oct 19, 2023 | Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a parti... |
| CVE-2023-41898 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is... |
| CVE-2023-41897 | CRITICAL | 9.6 | 0.9% | Oct 19, 2023 | Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, includin... |
| CVE-2023-41896 | CRITICAL | 9 | 0.3% | Oct 19, 2023 | Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure5... |
| CVE-2023-41895 | CRITICAL | 9.6 | 0.7% | Oct 19, 2023 | Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Ass... |
| CVE-2023-45819 | MEDIUM | 6.1 | 0.6% | Oct 19, 2023 | TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notif... |
| CVE-2023-45818 | MEDIUM | 6.1 | 0.6% | Oct 19, 2023 | TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyM... |
| CVE-2023-45815 | MEDIUM | 5.4 | 0.4% | Oct 19, 2023 | ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the... |
| CVE-2023-45280 | MEDIUM | 5.4 | 0.5% | Oct 19, 2023 | Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the up... |
| CVE-2023-45279 | MEDIUM | 5.4 | 0.4% | Oct 19, 2023 | Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the up... |
| CVE-2023-44690 | HIGH | 7.5 | 0.2% | Oct 19, 2023 | Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py |
| CVE-2023-43875 | MEDIUM | 6.1 | 0.8% | Oct 19, 2023 | Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to ex... |
| CVE-2023-43359 | MEDIUM | 5.4 | 0.5% | Oct 19, 2023 | Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a cra... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now