2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3462 | MEDIUM | 5.3 | 0.6% | Jul 31, 2023 | HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker m... |
| CVE-2023-39122 | CRITICAL | 9.8 | 0.6% | Jul 31, 2023 | BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This i... |
| CVE-2023-3983 | HIGH | 8.8 | 15.1% | Jul 31, 2023 | An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authentic... |
| CVE-2023-38989 | MEDIUM | 4.3 | 0.3% | Jul 31, 2023 | An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrar... |
| CVE-2023-4026 | — | — | — | Jul 31, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-4024. Reason: This record is a duplicate ... |
| CVE-2023-4010 | — | — | 0.6% | Jul 31, 2023 | Rejected reason: Rejected because the CVE description attributes a vulnerability to a non-existent Linux kernel function... |
| CVE-2023-4004 | HIGH | 7.8 | 1.0% | Jul 31, 2023 | A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove functio... |
| CVE-2023-3997 | HIGH | 7.8 | 0.3% | Jul 31, 2023 | Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s t... |
| CVE-2023-3817 | MEDIUM | 5.3 | 2.6% | Jul 31, 2023 | Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use ... |
| CVE-2023-38750 | HIGH | 7.5 | 0.7% | Jul 31, 2023 | In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and ... |
| CVE-2023-37771 | CRITICAL | 9.8 | 1.3% | Jul 31, 2023 | Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php. |
| CVE-2023-37580 | MEDIUM | 6.1 | 59.0% | Jul 31, 2023 | Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. |
| CVE-2023-34917 | MEDIUM | 6.1 | 0.4% | Jul 31, 2023 | Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java. |
| CVE-2023-34916 | MEDIUM | 6.1 | 0.4% | Jul 31, 2023 | Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java. |
| CVE-2023-38311 | MEDIUM | 5.4 | 0.5% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the System ... |
| CVE-2023-38310 | MEDIUM | 5.4 | 0.5% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the configu... |
| CVE-2023-38309 | MEDIUM | 6.1 | 0.6% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the pack... |
| CVE-2023-38308 | MEDIUM | 6.1 | 0.6% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel fu... |
| CVE-2023-38307 | MEDIUM | 5.4 | 0.4% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users a... |
| CVE-2023-38306 | MEDIUM | 6.1 | 0.5% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file up... |
| CVE-2023-38305 | MEDIUM | 6.1 | 0.5% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting... |
| CVE-2023-38304 | MEDIUM | 5.4 | 0.4% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users a... |
| CVE-2023-38303 | MEDIUM | 5.4 | 0.7% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. One can exploit a stored Cross-Site Scripting (XSS) attack to achieve Remote Co... |
| CVE-2023-35792 | MEDIUM | 6.1 | 0.3% | Jul 31, 2023 | Vound Intella Connect 2.6.0.3 is vulnerable to stored Cross-site Scripting (XSS). |
| CVE-2023-35791 | MEDIUM | 6.1 | 0.3% | Jul 31, 2023 | Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now