2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37212 | HIGH | 8.8 | 0.5% | Jul 5, 2023 | Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2023-37211 | HIGH | 8.8 | 0.7% | Jul 5, 2023 | Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidenc... |
| CVE-2023-37210 | MEDIUM | 6.5 | 0.2% | Jul 5, 2023 | A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confus... |
| CVE-2023-37209 | HIGH | 8.8 | 0.5% | Jul 5, 2023 | A use-after-free condition existed in `NotifyOnHistoryReload` where a `LoadingSessionHistoryEntry` object was freed and ... |
| CVE-2023-37206 | MEDIUM | 6.5 | 0.6% | Jul 5, 2023 | Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a ... |
| CVE-2023-37205 | MEDIUM | 6.5 | 0.4% | Jul 5, 2023 | The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerability affects Firefo... |
| CVE-2023-37204 | MEDIUM | 6.5 | 0.4% | Jul 5, 2023 | A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive... |
| CVE-2023-37203 | HIGH | 7.8 | 0.3% | Jul 5, 2023 | Insufficient validation in the Drag and Drop API in conjunction with social engineering, may have allowed an attacker to... |
| CVE-2023-2880 | HIGH | 7.5 | 0.7% | Jul 5, 2023 | Frauscher Sensortechnik GmbH FDS001 for FAdC/FAdCi v1.3.3 and all previous versions are vulnerable to a path traversal v... |
| CVE-2023-37208 | HIGH | 7.8 | 0.3% | Jul 5, 2023 | When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerabilit... |
| CVE-2023-37207 | MEDIUM | 6.5 | 0.7% | Jul 5, 2023 | A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, s... |
| CVE-2023-37202 | HIGH | 8.8 | 0.7% | Jul 5, 2023 | Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in t... |
| CVE-2023-37201 | HIGH | 8.8 | 0.7% | Jul 5, 2023 | An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerabi... |
| CVE-2023-34150 | MEDIUM | 5.3 | 1.1% | Jul 5, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage. |
| CVE-2023-35786 | MEDIUM | 4.9 | 2.5% | Jul 5, 2023 | Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files. |
| CVE-2023-33201 | MEDIUM | 5.3 | 0.8% | Jul 5, 2023 | Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applic... |
| CVE-2023-31999 | HIGH | 8.8 | 0.6% | Jul 4, 2023 | All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all req... |
| CVE-2023-3506 | MEDIUM | 6.1 | 0.3% | Jul 4, 2023 | A vulnerability was found in Active It Zone Active eCommerce CMS 6.5.0. It has been declared as problematic. This vulner... |
| CVE-2023-3505 | MEDIUM | 6.1 | 0.3% | Jul 4, 2023 | A vulnerability was found in Onest CRM 1.0. It has been classified as problematic. This affects an unknown part of the f... |
| CVE-2023-3504 | CRITICAL | 9.8 | 0.5% | Jul 4, 2023 | A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some ... |
| CVE-2023-3503 | HIGH | 8.8 | 0.8% | Jul 4, 2023 | A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulne... |
| CVE-2023-3502 | HIGH | 7.5 | 0.5% | Jul 4, 2023 | A vulnerability, which was classified as critical, was found in SourceCodester Shopping Website 1.0. Affected is an unkn... |
| CVE-2023-2974 | HIGH | 8.1 | 0.7% | Jul 4, 2023 | A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.ht... |
| CVE-2023-3460 | CRITICAL | 9.8 | 69.6% | Jul 4, 2023 | The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary c... |
| CVE-2023-3139 | MEDIUM | 6.1 | 0.7% | Jul 4, 2023 | The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now