2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34463 | HIGH | 8.1 | 0.6% | Jun 26, 2023 | DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In af... |
| CVE-2023-3113 | HIGH | 7.5 | 0.4% | Jun 26, 2023 | An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) ser... |
| CVE-2023-35933 | HIGH | 7.5 | 0.9% | Jun 26, 2023 | OPenFGA is an open source authorization/permission engine built for developers. OpenFGA versions v1.1.0 and prior are vu... |
| CVE-2023-35930 | MEDIUM | 5.3 | 0.4% | Jun 26, 2023 | SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical applica... |
| CVE-2023-35170 | — | — | — | Jun 26, 2023 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2023-34422 | MEDIUM | 6.5 | 0.4% | Jun 26, 2023 | A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a... |
| CVE-2023-34421 | MEDIUM | 6.5 | 0.4% | Jun 26, 2023 | A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically ... |
| CVE-2023-34420 | HIGH | 7.2 | 1.1% | Jun 26, 2023 | A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted call... |
| CVE-2023-34418 | HIGH | 8.1 | 0.5% | Jun 26, 2023 | A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to ... |
| CVE-2023-33404 | CRITICAL | 9.8 | 22.3% | Jun 26, 2023 | An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net vers... |
| CVE-2023-33176 | MEDIUM | 6.5 | 0.4% | Jun 26, 2023 | BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versio... |
| CVE-2023-2993 | MEDIUM | 6.3 | 0.2% | Jun 26, 2023 | A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API ca... |
| CVE-2023-2992 | HIGH | 7.5 | 0.5% | Jun 26, 2023 | An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which ca... |
| CVE-2023-2290 | MEDIUM | 6.7 | 0.2% | Jun 26, 2023 | A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elev... |
| CVE-2023-27082 | MEDIUM | 4.8 | 0.5% | Jun 26, 2023 | Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers t... |
| CVE-2023-36252 | HIGH | 8.8 | 0.7% | Jun 26, 2023 | An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code a... |
| CVE-2023-2005 | HIGH | 8.8 | 0.4% | Jun 26, 2023 | Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugi... |
| CVE-2023-33580 | MEDIUM | 4.8 | 3.7% | Jun 26, 2023 | Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f... |
| CVE-2023-29459 | MEDIUM | 6.1 | 0.6% | Jun 26, 2023 | The laola.redbull application through 5.1.9-R for Android exposes the exported activity at.redbullsalzburg.android.AppMo... |
| CVE-2023-28485 | MEDIUM | 5.4 | 1.0% | Jun 26, 2023 | A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticate... |
| CVE-2023-36301 | HIGH | 7.5 | 0.8% | Jun 26, 2023 | Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet. |
| CVE-2023-25307 | HIGH | 7.8 | 0.6% | Jun 26, 2023 | nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal. |
| CVE-2023-25306 | HIGH | 7.5 | 0.9% | Jun 26, 2023 | MultiMC Launcher <= 0.6.16 is vulnerable to Directory Traversal. |
| CVE-2023-30261 | CRITICAL | 9.8 | 27.1% | Jun 26, 2023 | Command Injection vulnerability in OpenWB 1.6 and 1.7 allows remote attackers to run arbitrary commands via crafted GET ... |
| CVE-2023-29438 | MEDIUM | 4.8 | 0.4% | Jun 26, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Martin SimpleModal Contact Form (SMCF) plugin <= ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now