2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43740 | HIGH | 8.8 | 1.2% | Sep 28, 2023 | Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_... |
| CVE-2023-43013 | CRITICAL | 9.8 | 0.7% | Sep 28, 2023 | Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter ... |
| CVE-2023-41911 | MEDIUM | 5.5 | 0.1% | Sep 28, 2023 | Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2). |
| CVE-2023-43323 | MEDIUM | 6.5 | 1.9% | Sep 28, 2023 | mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP a... |
| CVE-2023-43226 | HIGH | 8.8 | 0.9% | Sep 28, 2023 | An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute ... |
| CVE-2023-5256 | HIGH | 7.5 | 0.7% | Sep 28, 2023 | In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause se... |
| CVE-2023-43664 | MEDIUM | 4.3 | 0.4% | Sep 28, 2023 | PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list a... |
| CVE-2023-43663 | MEDIUM | 4.3 | 0.3% | Sep 28, 2023 | PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled ... |
| CVE-2023-43657 | MEDIUM | 6.1 | 0.5% | Sep 28, 2023 | discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encry... |
| CVE-2023-43044 | HIGH | 7.5 | 0.8% | Sep 28, 2023 | IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send ... |
| CVE-2023-40375 | HIGH | 7.8 | 0.1% | Sep 28, 2023 | Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A m... |
| CVE-2023-39195 | — | — | — | Sep 28, 2023 | Rejected reason: CVE-2023-39195 was found to be a duplicate of CVE-2023-42755. Please see https://access.redhat.com/secu... |
| CVE-2023-5217 | HIGH | 8.8 | 34.4% | Sep 28, 2023 | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remo... |
| CVE-2023-5187 | HIGH | 8.8 | 0.8% | Sep 28, 2023 | Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to instal... |
| CVE-2023-5186 | HIGH | 8.8 | 1.0% | Sep 28, 2023 | Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to e... |
| CVE-2023-30415 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the... |
| CVE-2023-43884 | MEDIUM | 5.4 | 0.4% | Sep 28, 2023 | A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attacke... |
| CVE-2023-43879 | MEDIUM | 4.8 | 0.5% | Sep 28, 2023 | Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafte... |
| CVE-2023-43878 | MEDIUM | 5.4 | 0.5% | Sep 28, 2023 | Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via ... |
| CVE-2023-43876 | MEDIUM | 5.4 | 0.4% | Sep 28, 2023 | A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary w... |
| CVE-2023-5215 | MEDIUM | 6.5 | 0.7% | Sep 28, 2023 | A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-... |
| CVE-2023-43874 | MEDIUM | 5.4 | 0.6% | Sep 28, 2023 | Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code ... |
| CVE-2023-43873 | MEDIUM | 5.4 | 0.5% | Sep 28, 2023 | A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a c... |
| CVE-2023-43872 | MEDIUM | 5.4 | 0.5% | Sep 28, 2023 | A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Sit... |
| CVE-2023-43871 | MEDIUM | 5.4 | 0.4% | Sep 28, 2023 | A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scriptin... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now