2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40711 | HIGH | 7.5 | 0.7% | Aug 20, 2023 | Veilid before 0.1.9 does not check the size of uncompressed data during decompression upon an envelope receipt, which al... |
| CVE-2023-2971 | MEDIUM | 6.5 | 0.4% | Aug 19, 2023 | Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files an... |
| CVE-2023-2318 | CRITICAL | 9.6 | 0.5% | Aug 19, 2023 | DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows... |
| CVE-2023-2317 | CRITICAL | 9.6 | 2.2% | Aug 19, 2023 | DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run a... |
| CVE-2023-2316 | HIGH | 7.4 | 0.6% | Aug 19, 2023 | Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and ex... |
| CVE-2023-2110 | HIGH | 7.1 | 0.3% | Aug 19, 2023 | Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access l... |
| CVE-2023-4433 | MEDIUM | 5.4 | 0.5% | Aug 19, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. |
| CVE-2023-4432 | MEDIUM | 6.1 | 0.5% | Aug 19, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. |
| CVE-2023-40175 | CRITICAL | 9.8 | 0.7% | Aug 18, 2023 | Puma is a Ruby/Rack web server built for parallelism. Prior to versions 6.3.1 and 5.6.7, puma exhibited incorrect behavi... |
| CVE-2023-40174 | CRITICAL | 9.8 | 0.4% | Aug 18, 2023 | Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html... |
| CVE-2023-40173 | HIGH | 7.5 | 0.5% | Aug 18, 2023 | Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html... |
| CVE-2023-40172 | HIGH | 8.8 | 0.2% | Aug 18, 2023 | Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html... |
| CVE-2023-40037 | MEDIUM | 6.5 | 1.5% | Aug 18, 2023 | Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with co... |
| CVE-2023-38839 | HIGH | 7.5 | 0.7% | Aug 18, 2023 | SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via theID... |
| CVE-2023-20212 | HIGH | 7.5 | 2.6% | Aug 18, 2023 | A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of serv... |
| CVE-2023-4422 | MEDIUM | 4.8 | 0.6% | Aug 18, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. |
| CVE-2023-38911 | MEDIUM | 5.4 | 0.5% | Aug 18, 2023 | A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted pay... |
| CVE-2023-38910 | MEDIUM | 6.1 | 0.4% | Aug 18, 2023 | CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HT... |
| CVE-2023-38890 | HIGH | 8.8 | 1.0% | Aug 18, 2023 | Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form,... |
| CVE-2023-27471 | MEDIUM | 5.5 | 0.2% | Aug 18, 2023 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect a... |
| CVE-2023-4415 | HIGH | 8.8 | 56.1% | Aug 18, 2023 | A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is s... |
| CVE-2023-4414 | CRITICAL | 9.8 | 17.8% | Aug 18, 2023 | A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230807. It has been declared as critical. Aff... |
| CVE-2023-32130 | MEDIUM | 4.8 | 0.4% | Aug 18, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.6 versions. |
| CVE-2023-32122 | MEDIUM | 6.1 | 0.3% | Aug 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spiffy Plugins Spiffy Calendar plugin <= 4.9.3 versions. |
| CVE-2023-4413 | — | — | — | Aug 18, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn b... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now