2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3396 | MEDIUM | 6.5 | 0.5% | Jun 25, 2023 | A vulnerability was found in Campcodes Retro Cellphone Online Store 1.0. It has been declared as critical. Affected by t... |
| CVE-2023-36632 | HIGH | 7.5 | 1.3% | Jun 25, 2023 | The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum ... |
| CVE-2023-36630 | HIGH | 8.8 | 0.7% | Jun 25, 2023 | In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass. |
| CVE-2023-36612 | HIGH | 7.5 | 0.8% | Jun 25, 2023 | Directory traversal can occur in the Basecamp com.basecamp.bc3 application before 4.2.1 for Android, which may allow an ... |
| CVE-2023-3388 | MEDIUM | 6.1 | 84.5% | Jun 24, 2023 | The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_... |
| CVE-2023-3387 | MEDIUM | 5.4 | 0.5% | Jun 24, 2023 | The Lana Text to Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lana_text_to_image' an... |
| CVE-2023-3197 | CRITICAL | 9.8 | 3.9% | Jun 24, 2023 | The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versi... |
| CVE-2023-1722 | HIGH | 8.8 | 0.4% | Jun 24, 2023 | Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible b... |
| CVE-2023-1724 | MEDIUM | 5.4 | 0.5% | Jun 24, 2023 | Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the... |
| CVE-2023-1721 | HIGH | 7.2 | 1.0% | Jun 24, 2023 | Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible b... |
| CVE-2023-35932 | HIGH | 8.8 | 1.8% | Jun 23, 2023 | jcvi is a Python library to facilitate genome assembly, annotation, and comparative genomics. A configuration injection ... |
| CVE-2023-1783 | HIGH | 7.6 | 0.6% | Jun 23, 2023 | OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible bec... |
| CVE-2023-35928 | HIGH | 8.8 | 1.0% | Jun 23, 2023 | Nextcloud Server is a space for data storage on Nextcloud, a self-hosted productivity playform. In NextCloud Server vers... |
| CVE-2023-35927 | HIGH | 8.1 | 0.8% | Jun 23, 2023 | NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform... |
| CVE-2023-35173 | MEDIUM | 6.5 | 0.5% | Jun 23, 2023 | Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client sid... |
| CVE-2023-35172 | CRITICAL | 9.1 | 0.9% | Jun 23, 2023 | NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform... |
| CVE-2023-35171 | MEDIUM | 6.1 | 0.6% | Jun 23, 2023 | NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform... |
| CVE-2023-35169 | CRITICAL | 9.8 | 3.2% | Jun 23, 2023 | PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Pr... |
| CVE-2023-35165 | HIGH | 8.8 | 0.9% | Jun 23, 2023 | AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in c... |
| CVE-2023-35163 | MEDIUM | 5.2 | 0.5% | Jun 23, 2023 | Vega is a decentralized trading platform that allows pseudo-anonymous trading of derivatives on a blockchain. Prior to v... |
| CVE-2023-35154 | MEDIUM | 6.5 | 0.4% | Jun 23, 2023 | Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.... |
| CVE-2023-34254 | HIGH | 7.2 | 0.8% | Jun 23, 2023 | The GLPI Agent is a generic management agent. Prior to version 1.5, if glpi-agent is running remoteinventory task agains... |
| CVE-2023-3212 | MEDIUM | 4.4 | 0.3% | Jun 23, 2023 | A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file s... |
| CVE-2023-36348 | HIGH | 8.8 | 6.4% | Jun 23, 2023 | POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename p... |
| CVE-2023-36346 | MEDIUM | 6.1 | 5.3% | Jun 23, 2023 | POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now