2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25004 | HIGH | 7.8 | 0.2% | Jun 27, 2023 | A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploi... |
| CVE-2023-23468 | MEDIUM | 5.5 | 0.2% | Jun 27, 2023 | IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to insuffic... |
| CVE-2023-22593 | HIGH | 7.8 | 0.2% | Jun 27, 2023 | IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to securit... |
| CVE-2023-34839 | MEDIUM | 6.8 | 0.5% | Jun 27, 2023 | A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain priv... |
| CVE-2023-34838 | MEDIUM | 5.4 | 0.8% | Jun 27, 2023 | A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remot... |
| CVE-2023-34837 | MEDIUM | 5.4 | 0.8% | Jun 27, 2023 | A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remot... |
| CVE-2023-34836 | MEDIUM | 5.4 | 0.8% | Jun 27, 2023 | A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remot... |
| CVE-2023-34835 | MEDIUM | 5.4 | 0.6% | Jun 27, 2023 | A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remot... |
| CVE-2023-33567 | — | — | — | Jun 27, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-33566 | — | — | — | Jun 27, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-28857 | HIGH | 7.5 | 0.4% | Jun 27, 2023 | Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authe... |
| CVE-2023-26276 | HIGH | 7.5 | 0.4% | Jun 27, 2023 | IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly ... |
| CVE-2023-26274 | MEDIUM | 5.4 | 0.4% | Jun 27, 2023 | IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr... |
| CVE-2023-26273 | MEDIUM | 4.3 | 0.4% | Jun 27, 2023 | IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validatio... |
| CVE-2023-35800 | MEDIUM | 4.3 | 0.3% | Jun 27, 2023 | Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution ... |
| CVE-2023-35799 | MEDIUM | 5.5 | 0.2% | Jun 27, 2023 | Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SE... |
| CVE-2023-34830 | MEDIUM | 5.4 | 0.7% | Jun 27, 2023 | i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter... |
| CVE-2023-34240 | CRITICAL | 9.8 | 0.4% | Jun 27, 2023 | Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target f... |
| CVE-2023-34099 | MEDIUM | 5.3 | 0.5% | Jun 27, 2023 | Shopware is an open source e-commerce software. The mail validation in the registration process had some flaws, so it wa... |
| CVE-2023-34098 | MEDIUM | 5.3 | 0.5% | Jun 27, 2023 | Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configura... |
| CVE-2023-32339 | MEDIUM | 6.1 | 0.5% | Jun 27, 2023 | IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2023-3432 | CRITICAL | 10 | 0.7% | Jun 27, 2023 | Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9. |
| CVE-2023-3431 | MEDIUM | 5.3 | 0.7% | Jun 27, 2023 | Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9. |
| CVE-2023-3405 | HIGH | 7.5 | 0.7% | Jun 27, 2023 | Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonym... |
| CVE-2023-36002 | MEDIUM | 4.3 | 0.2% | Jun 27, 2023 | A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an an... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now