2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4673 | CRITICAL | 9.8 | 0.6% | Sep 15, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sanalogy Turasista... |
| CVE-2023-3378 | — | — | — | Sep 15, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2023-36659 | CRITICAL | 9.8 | 0.7% | Sep 15, 2023 | An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Long inputs were not properly processed, which allows r... |
| CVE-2023-36657 | CRITICAL | 9.8 | 0.6% | Sep 15, 2023 | An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrat... |
| CVE-2023-36658 | HIGH | 7.8 | 0.2% | Sep 15, 2023 | An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused loca... |
| CVE-2023-40983 | MEDIUM | 6.1 | 0.5% | Sep 15, 2023 | A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to e... |
| CVE-2023-38039 | HIGH | 7.5 | 62.2% | Sep 15, 2023 | When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl ... |
| CVE-2023-4974 | CRITICAL | 9.8 | 4.9% | Sep 15, 2023 | A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown func... |
| CVE-2023-4963 | MEDIUM | 5.4 | 0.4% | Sep 15, 2023 | The WS Facebook Like Box Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ws-facebook-likeb... |
| CVE-2023-40982 | MEDIUM | 5.4 | 0.4% | Sep 15, 2023 | A stored cross-site scripting (XSS) vulnerability in Webmin v2.100 allows attackers to execute arbitrary web scripts or ... |
| CVE-2023-3891 | HIGH | 7 | 0.3% | Sep 15, 2023 | Race condition in Lapce v0.2.8 allows an attacker to elevate privileges on the system |
| CVE-2023-4973 | MEDIUM | 6.1 | 1.8% | Sep 15, 2023 | A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerabi... |
| CVE-2023-4982 | MEDIUM | 5.4 | 0.6% | Sep 15, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0. |
| CVE-2023-4981 | MEDIUM | 5.4 | 0.6% | Sep 15, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0. |
| CVE-2023-4980 | MEDIUM | 5.4 | 0.6% | Sep 15, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0. |
| CVE-2023-4979 | MEDIUM | 5.4 | 0.6% | Sep 15, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0. |
| CVE-2023-4978 | MEDIUM | 6.1 | 0.6% | Sep 15, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0. |
| CVE-2023-4977 | MEDIUM | 5.4 | 0.4% | Sep 15, 2023 | Code Injection in GitHub repository librenms/librenms prior to 23.9.0. |
| CVE-2023-40986 | MEDIUM | 5.4 | 0.4% | Sep 15, 2023 | A stored cross-site scripting (XSS) vulnerability in the Usermin Configuration function of Webmin v2.100 allows attacker... |
| CVE-2023-40985 | MEDIUM | 5.4 | 0.4% | Sep 15, 2023 | An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scrip... |
| CVE-2023-40984 | MEDIUM | 5.4 | 0.4% | Sep 15, 2023 | A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to e... |
| CVE-2023-39643 | CRITICAL | 9.8 | 0.7% | Sep 15, 2023 | Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml... |
| CVE-2023-4680 | MEDIUM | 6.8 | 0.4% | Sep 15, 2023 | HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even w... |
| CVE-2023-40958 | HIGH | 8.8 | 1.1% | Sep 15, 2023 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fix... |
| CVE-2023-40957 | HIGH | 8.8 | 1.1% | Sep 15, 2023 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fix... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now