2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36462 | MEDIUM | 5.4 | 0.5% | Jul 6, 2023 | Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 2.6.0 and prior to versi... |
| CVE-2023-35934 | HIGH | 8.2 | 0.9% | Jul 6, 2023 | yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external down... |
| CVE-2023-30195 | HIGH | 7.5 | 0.4% | Jul 6, 2023 | In the module "Detailed Order" (lgdetailedorder) in version up to 1.1.20 from Linea Grafica for PrestaShop, a guest can ... |
| CVE-2023-3529 | HIGH | 7.5 | 0.4% | Jul 6, 2023 | A vulnerability classified as problematic has been found in Rotem Dynamics Rotem CRM up to 20230729. This affects an unk... |
| CVE-2023-36461 | HIGH | 7.5 | 1.1% | Jul 6, 2023 | Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Masto... |
| CVE-2023-36460 | CRITICAL | 9.9 | 37.3% | Jul 6, 2023 | Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versi... |
| CVE-2023-36459 | MEDIUM | 6.1 | 1.1% | Jul 6, 2023 | Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 1.3 and prior to version... |
| CVE-2023-36456 | HIGH | 7.3 | 0.6% | Jul 6, 2023 | authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the so... |
| CVE-2023-3528 | CRITICAL | 9.8 | 0.4% | Jul 6, 2023 | A vulnerability was found in ThinuTech ThinuCMS 1.5. It has been rated as critical. Affected by this issue is some unkno... |
| CVE-2023-1298 | MEDIUM | 6.1 | 0.3% | Jul 6, 2023 | ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was ... |
| CVE-2023-37454 | MEDIUM | 5.5 | 0.4% | Jul 6, 2023 | An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write ... |
| CVE-2023-37453 | MEDIUM | 4.6 | 0.6% | Jul 6, 2023 | An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in r... |
| CVE-2023-37260 | HIGH | 7.5 | 0.8% | Jul 6, 2023 | league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2... |
| CVE-2023-36830 | HIGH | 7.8 | 0.4% | Jul 6, 2023 | SQLFluff is a SQL linter. Prior to version 2.1.2, in environments where untrusted users have access to the config files,... |
| CVE-2023-36823 | MEDIUM | 6.1 | 0.6% | Jul 6, 2023 | Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak a... |
| CVE-2023-34193 | HIGH | 8.8 | 1.2% | Jul 6, 2023 | File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obt... |
| CVE-2023-34192 | CRITICAL | 9 | 77.3% | Jul 6, 2023 | Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary co... |
| CVE-2023-30321 | CRITICAL | 9 | 0.9% | Jul 6, 2023 | Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine... |
| CVE-2023-30320 | CRITICAL | 9 | 0.9% | Jul 6, 2023 | Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine c... |
| CVE-2023-30319 | CRITICAL | 9.6 | 0.8% | Jul 6, 2023 | Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine co... |
| CVE-2023-29382 | CRITICAL | 9.8 | 1.0% | Jul 6, 2023 | An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preaut... |
| CVE-2023-29381 | CRITICAL | 9.8 | 1.0% | Jul 6, 2023 | An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sen... |
| CVE-2023-37136 | MEDIUM | 5.4 | 0.3% | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attac... |
| CVE-2023-37135 | MEDIUM | 5.4 | 0.3% | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execu... |
| CVE-2023-37134 | MEDIUM | 5.4 | 0.3% | Jul 6, 2023 | A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now