2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-33564MEDIUM6.1There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Boo...
CVE-2023-33563HIGH8.8In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on...
CVE-2023-33562CRITICAL9.8User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery...
CVE-2023-33561CRITICAL9.8Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure pas...
CVE-2023-33560MEDIUM6.1There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking C...
CVE-2023-31427HIGH7.8Brocade Fabric OS versions before Brocade Fabric OS v9.1.1c, and v9.2.0 Could allow an authenticated, local user with kn...
CVE-2023-31426MEDIUM6.5 The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 ...
CVE-2023-31429MEDIUM5.5Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “c...
CVE-2023-31425HIGH7.8A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS...
CVE-2023-3718HIGH8.8 An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation o...
CVE-2023-20583MEDIUM4.7A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU po...
CVE-2023-39147HIGH7.8An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafte...
CVE-2023-34552HIGH8.8In certain EZVIZ products, two stack based buffer overflows in mulicast_parse_sadp_packet and mulicast_get_pack_type fun...
CVE-2023-34551HIGH8In certain EZVIZ products, two stack buffer overflows in netClientSetWlanCfg function of the EZVIZ SDK command server ca...
CVE-2023-38560MEDIUM5.5An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local ...
CVE-2023-38559MEDIUM5.5A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a ...
CVE-2023-36211MEDIUM5.4The Barebones CMS v2.0.2 is vulnerable to Stored Cross-Site Scripting (XSS) when an authenticated user interacts with ce...
CVE-2023-36210CRITICAL9.8MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerab...
CVE-2023-33493CRITICAL9.8An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmana...
CVE-2023-4058CRITICAL9.8Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2023-4057CRITICAL9.8Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence ...
CVE-2023-4056CRITICAL9.8Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102...
CVE-2023-4055HIGH7.5When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no l...
CVE-2023-4054MEDIUM5.5When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only...
CVE-2023-4053MEDIUM6.5A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now