2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40758 | CRITICAL | 9.8 | 0.7% | Aug 28, 2023 | User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a diffe... |
| CVE-2023-40757 | CRITICAL | 9.8 | 0.7% | Aug 28, 2023 | User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a d... |
| CVE-2023-40756 | CRITICAL | 9.8 | 0.7% | Aug 28, 2023 | User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a differ... |
| CVE-2023-40755 | MEDIUM | 6.1 | 1.2% | Aug 28, 2023 | There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widge... |
| CVE-2023-40754 | HIGH | 8.8 | 0.7% | Aug 28, 2023 | In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile... |
| CVE-2023-40753 | MEDIUM | 5.4 | 1.1% | Aug 28, 2023 | There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support S... |
| CVE-2023-40752 | MEDIUM | 6.1 | 1.0% | Aug 28, 2023 | There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer W... |
| CVE-2023-40751 | MEDIUM | 6.1 | 1.0% | Aug 28, 2023 | PHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php. |
| CVE-2023-40750 | MEDIUM | 6.1 | 1.0% | Aug 28, 2023 | There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing S... |
| CVE-2023-40749 | CRITICAL | 9.8 | 3.3% | Aug 28, 2023 | PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php. |
| CVE-2023-40748 | CRITICAL | 9.8 | 2.9% | Aug 28, 2023 | PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php. |
| CVE-2023-36481 | HIGH | 7.5 | 0.5% | Aug 28, 2023 | An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor 9810, 9610, 9820, 980, 850, 1080, 2100... |
| CVE-2023-34758 | HIGH | 8.1 | 0.6% | Aug 28, 2023 | Sliver from v1.5.x to v1.5.39 has an improper cryptographic implementation, which allows attackers to execute a man-in-t... |
| CVE-2023-26095 | HIGH | 7.5 | 0.6% | Aug 28, 2023 | ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a cr... |
| CVE-2023-40195 | HIGH | 8.8 | 1.4% | Aug 28, 2023 | Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Soft... |
| CVE-2023-27604 | HIGH | 8.8 | 1.2% | Aug 28, 2023 | Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parame... |
| CVE-2023-38030 | HIGH | 7.5 | 0.6% | Aug 28, 2023 | Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. A... |
| CVE-2023-38029 | CRITICAL | 9.8 | 0.8% | Aug 28, 2023 | Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within t... |
| CVE-2023-38028 | CRITICAL | 9.1 | 0.7% | Aug 28, 2023 | Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can... |
| CVE-2023-38027 | CRITICAL | 9.8 | 1.2% | Aug 28, 2023 | SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthen... |
| CVE-2023-38026 | CRITICAL | 9.8 | 0.6% | Aug 28, 2023 | SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can explo... |
| CVE-2023-38025 | CRITICAL | 9.8 | 1.2% | Aug 28, 2023 | SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthe... |
| CVE-2023-38024 | CRITICAL | 9.8 | 0.6% | Aug 28, 2023 | SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An... |
| CVE-2023-4561 | MEDIUM | 4.8 | 0.5% | Aug 28, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.4. |
| CVE-2023-4560 | MEDIUM | 6.5 | 0.6% | Aug 28, 2023 | Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now