2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3485LOW3.6Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task...
CVE-2023-37360MEDIUM6.1pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the ...
CVE-2023-37307MEDIUM5.4In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
CVE-2023-37306HIGH7.5MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive informati...
CVE-2023-37305MEDIUM5.3An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Pa...
CVE-2023-37304MEDIUM5.4An issue was discovered in the DoubleWiki extension for MediaWiki through 1.39.3. includes/DoubleWiki.php allows XSS via...
CVE-2023-37303CRITICAL9.8An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In certain situations, an attempt to bl...
CVE-2023-37302MEDIUM6.1An issue was discovered in SiteLinksView.php in Wikibase in MediaWiki through 1.39.3. There is XSS via a crafted badge t...
CVE-2023-37301MEDIUM5.3An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn't use EditEntity...
CVE-2023-37300MEDIUM5.3An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorr...
CVE-2023-35178HIGH8.8Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow when performing a GET request to sc...
CVE-2023-35177HIGH8.8Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compac...
CVE-2023-35176HIGH8.8Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Denial of Service when using...
CVE-2023-35175CRITICAL9.8Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of...
CVE-2023-34840MEDIUM6.1angular-ui-notification v0.1.0, v0.2.0, and v0.3.6 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2023-26299HIGH7A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI ...
CVE-2023-37299MEDIUM6.1Joplin before 2.11.5 allows XSS via an AREA element of an image map.
CVE-2023-37298MEDIUM6.1Joplin before 2.11.5 allows XSS via a USE element in an SVG document.
CVE-2023-33276MEDIUM6.1The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 responds with a "404 - Not Found" status ...
CVE-2023-3478HIGH7.2A vulnerability classified as critical was found in IBOS OA 4.5.5. Affected by this vulnerability is the function action...
CVE-2023-3479MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.
CVE-2023-3477MEDIUM6.1A vulnerability was found in RocketSoft Rocket LMS 1.7. It has been declared as problematic. This vulnerability affects ...
CVE-2023-3476MEDIUM6.1A vulnerability was found in SimplePHPscripts GuestBook Script 2.2. It has been classified as problematic. This affects ...
CVE-2023-3475MEDIUM6.1A vulnerability was found in SimplePHPscripts Event Script 2.1 and classified as problematic. Affected by this issue is ...
CVE-2023-3474MEDIUM6.1A vulnerability has been found in SimplePHPscripts Simple Blog 3.2 and classified as problematic. Affected by this vulne...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now