2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-24420 | MEDIUM | 6.1 | 0.4% | Jun 15, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact F... |
| CVE-2023-3276 | HIGH | 7.5 | 0.7% | Jun 15, 2023 | A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this is... |
| CVE-2023-3275 | CRITICAL | 9.8 | 0.5% | Jun 15, 2023 | A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnera... |
| CVE-2023-3274 | HIGH | 8.8 | 0.9% | Jun 15, 2023 | A vulnerability classified as critical has been found in code-projects Supplier Management System 1.0. Affected is an un... |
| CVE-2023-25972 | MEDIUM | 4.8 | 0.4% | Jun 15, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in IKSWEB WordPress Старт plugin <= 3.7 versions. |
| CVE-2023-25450 | HIGH | 8.8 | 0.3% | Jun 15, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin <= 2.... |
| CVE-2023-23802 | HIGH | 8.8 | 0.3% | Jun 15, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions... |
| CVE-2023-25449 | HIGH | 8.8 | 0.3% | Jun 15, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions. |
| CVE-2023-32229 | MEDIUM | 6.5 | 0.6% | Jun 15, 2023 | Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the ... |
| CVE-2023-28175 | HIGH | 7.7 | 0.5% | Jun 15, 2023 | Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access ... |
| CVE-2023-2847 | HIGH | 7.8 | 0.1% | Jun 15, 2023 | During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with th... |
| CVE-2023-35030 | HIGH | 8.8 | 0.4% | Jun 15, 2023 | Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 thro... |
| CVE-2023-2270 | HIGH | 7.8 | 0.3% | Jun 15, 2023 | The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start variou... |
| CVE-2023-3193 | MEDIUM | 6.1 | 0.5% | Jun 15, 2023 | Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4... |
| CVE-2023-35029 | MEDIUM | 6.1 | 0.5% | Jun 15, 2023 | Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Li... |
| CVE-2023-25683 | HIGH | 7.5 | 0.6% | Jun 15, 2023 | IBM PowerVM Hypervisor FW950.00 through FW950.71, FW1010.00 through FW1010.40, FW1020.00 through FW1020.20, and FW1030.0... |
| CVE-2023-34452 | MEDIUM | 6.1 | 0.6% | Jun 14, 2023 | Grav is a flat-file content management system. In versions 1.7.42 and prior, the "/forgot_password" page has a self-refl... |
| CVE-2023-34448 | HIGH | 7.2 | 4.5% | Jun 14, 2023 | Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side templ... |
| CVE-2023-34253 | HIGH | 7.2 | 2.1% | Jun 14, 2023 | Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prev... |
| CVE-2023-34252 | HIGH | 7.2 | 2.1% | Jun 14, 2023 | Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filt... |
| CVE-2023-34251 | HIGH | 7.2 | 2.3% | Jun 14, 2023 | Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection... |
| CVE-2023-2820 | MEDIUM | 6.8 | 0.3% | Jun 14, 2023 | An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (... |
| CVE-2023-2819 | MEDIUM | 4.3 | 0.3% | Jun 14, 2023 | A stored cross-site scripting vulnerability in the Sources UI in Proofpoint Threat Response/ Threat Response Auto Pull (... |
| CVE-2023-34565 | MEDIUM | 5.4 | 0.4% | Jun 14, 2023 | Netbox 3.5.1 is vulnerable to Cross Site Scripting (XSS) in the "Create Wireless LAN Groups" function. |
| CVE-2023-34449 | MEDIUM | 5.3 | 1.0% | Jun 14, 2023 | ink! is an embedded domain specific language to write smart contracts in Rust for blockchains built on the Substrate fra... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now