2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38870 | CRITICAL | 9.8 | 0.8% | Sep 28, 2023 | A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book ha... |
| CVE-2023-42222 | HIGH | 8.8 | 1.4% | Sep 28, 2023 | WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal funct... |
| CVE-2023-41450 | HIGH | 8.8 | 1.4% | Sep 28, 2023 | An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to t... |
| CVE-2023-41447 | MEDIUM | 6.1 | 0.8% | Sep 28, 2023 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-41446 | MEDIUM | 6.1 | 0.8% | Sep 28, 2023 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-41444 | HIGH | 7.8 | 0.3% | Sep 28, 2023 | An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privile... |
| CVE-2023-5244 | MEDIUM | 6.1 | 1.1% | Sep 28, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0. |
| CVE-2023-43320 | HIGH | 8.8 | 1.0% | Sep 27, 2023 | An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxm... |
| CVE-2023-43314 | HIGH | 7.5 | 0.7% | Sep 27, 2023 | ** UNSUPPORTED WHEN ASSIGNED **The buffer overflow vulnerability in the Zyxel PMG2005-T20B firmware version V1.00(ABNK.2... |
| CVE-2023-43233 | MEDIUM | 6.1 | 0.3% | Sep 27, 2023 | A stored cross-site scripting (XSS) vulnerability in the cms/content/edit component of YZNCMS v1.3.0 allows attackers to... |
| CVE-2023-43191 | MEDIUM | 5.4 | 0.3% | Sep 27, 2023 | SpringbootCMS 1.0 foreground message can be embedded malicious code saved in the database. When users browse the comment... |
| CVE-2023-41453 | MEDIUM | 6.1 | 0.8% | Sep 27, 2023 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-41452 | HIGH | 8.8 | 0.6% | Sep 27, 2023 | Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary ... |
| CVE-2023-41451 | MEDIUM | 6.1 | 0.8% | Sep 27, 2023 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-41449 | CRITICAL | 9.8 | 1.5% | Sep 27, 2023 | An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to t... |
| CVE-2023-41448 | MEDIUM | 6.1 | 0.8% | Sep 27, 2023 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-41445 | MEDIUM | 6.1 | 0.7% | Sep 27, 2023 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-44080 | CRITICAL | 9.8 | 0.9% | Sep 27, 2023 | An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request... |
| CVE-2023-43660 | HIGH | 8.1 | 0.3% | Sep 27, 2023 | Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verif... |
| CVE-2023-43192 | HIGH | 8.8 | 0.7% | Sep 27, 2023 | SQL injection can exist in a newly created part of the SpringbootCMS 1.0 background, and the parameters submitted by use... |
| CVE-2023-4066 | MEDIUM | 5.5 | 0.2% | Sep 27, 2023 | A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, de... |
| CVE-2023-43656 | CRITICAL | 9 | 0.3% | Sep 27, 2023 | matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that ... |
| CVE-2023-43651 | CRITICAL | 9.9 | 1.7% | Sep 27, 2023 | JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to exec... |
| CVE-2023-42818 | CRITICAL | 9.8 | 0.6% | Sep 27, 2023 | JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH s... |
| CVE-2023-40026 | MEDIUM | 4.3 | 0.5% | Sep 27, 2023 | Argo CD is a declarative continuous deployment framework for Kubernetes. In Argo CD versions prior to 2.3 (starting at l... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now