2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3286 | MEDIUM | 6.5 | 0.3% | Jul 9, 2024 | A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in th... |
| CVE-2023-51778 | MEDIUM | 5.5 | 0.2% | Jul 2, 2024 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen... |
| CVE-2023-51777 | MEDIUM | 5.5 | 0.2% | Jul 2, 2024 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue sc... |
| CVE-2023-41928 | MEDIUM | 5.3 | 0.1% | Jul 2, 2024 | The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weaknesses. |
| CVE-2023-41927 | MEDIUM | 5.3 | 0.1% | Jul 2, 2024 | The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be phased out, increasing... |
| CVE-2023-41922 | MEDIUM | 5.4 | 0.2% | Jul 2, 2024 | A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation,... |
| CVE-2023-50964 | MEDIUM | 5.4 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2023-50953 | MEDIUM | 4.3 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec... |
| CVE-2023-50952 | MEDIUM | 5.4 | 0.2% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authentica... |
| CVE-2023-50954 | MEDIUM | 5.3 | 0.4% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further at... |
| CVE-2023-4017 | MEDIUM | 6.1 | 0.4% | Jun 29, 2024 | The Goya theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attra-color’, 'attra-size', and '... |
| CVE-2023-47803 | MEDIUM | 5.3 | 0.7% | Jun 28, 2024 | A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the... |
| CVE-2023-38370 | MEDIUM | 6.5 | 0.7% | Jun 27, 2024 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the ne... |
| CVE-2023-38368 | MEDIUM | 5.5 | 0.2% | Jun 27, 2024 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do ... |
| CVE-2023-42014 | MEDIUM | 5.4 | 0.3% | Jun 27, 2024 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.2.0.2 is vulnerable to cross-site scripting. This vulnera... |
| CVE-2023-42011 | MEDIUM | 5.4 | 0.2% | Jun 27, 2024 | IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI ... |
| CVE-2023-30430 | MEDIUM | 5.5 | 0.2% | Jun 27, 2024 | IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from trace l... |
| CVE-2023-7270 | MEDIUM | 5.3 | 0.3% | Jun 27, 2024 | An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision... |
| CVE-2023-26877 | MEDIUM | 6.3 | 0.4% | Jun 26, 2024 | File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .p... |
| CVE-2023-37541 | MEDIUM | 4.3 | 0.3% | Jun 25, 2024 | HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai... |
| CVE-2023-45195 | MEDIUM | 5.3 | 0.4% | Jun 24, 2024 | Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote... |
| CVE-2023-49793 | MEDIUM | 6.5 | 0.7% | Jun 24, 2024 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Z... |
| CVE-2023-39517 | MEDIUM | 5.4 | 0.5% | Jun 21, 2024 | Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected ... |
| CVE-2023-38506 | MEDIUM | 5.4 | 0.4% | Jun 21, 2024 | Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows pasti... |
| CVE-2023-37898 | MEDIUM | 5.4 | 0.4% | Jun 21, 2024 | Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an un... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now