2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49977 | MEDIUM | 5.4 | 0.4% | Mar 6, 2024 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip... |
| CVE-2023-49976 | MEDIUM | 5.4 | 0.5% | Mar 6, 2024 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip... |
| CVE-2023-49974 | MEDIUM | 6.1 | 0.4% | Mar 6, 2024 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip... |
| CVE-2023-49973 | MEDIUM | 6.1 | 0.4% | Mar 6, 2024 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip... |
| CVE-2023-49971 | MEDIUM | 6.1 | 0.4% | Mar 6, 2024 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scrip... |
| CVE-2023-48644 | MEDIUM | 6.1 | 0.3% | Mar 5, 2024 | An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feat... |
| CVE-2023-45290 | MEDIUM | 6.5 | 1.2% | Mar 5, 2024 | When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, R... |
| CVE-2023-45289 | MEDIUM | 4.3 | 1.1% | Mar 5, 2024 | When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http... |
| CVE-2023-26282 | MEDIUM | 4.2 | 0.2% | Mar 5, 2024 | IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the sy... |
| CVE-2023-25681 | MEDIUM | 6.5 | 0.6% | Mar 5, 2024 | LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authentic... |
| CVE-2023-45598 | MEDIUM | 5.3 | 0.5% | Mar 5, 2024 | A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allow... |
| CVE-2023-45596 | MEDIUM | 5.3 | 0.5% | Mar 5, 2024 | A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web applic... |
| CVE-2023-45594 | MEDIUM | 6.8 | 0.3% | Mar 5, 2024 | A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a ... |
| CVE-2023-45593 | MEDIUM | 6.8 | 0.3% | Mar 5, 2024 | A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling... |
| CVE-2023-49969 | MEDIUM | 4.3 | 0.5% | Mar 5, 2024 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_sup... |
| CVE-2023-41829 | MEDIUM | 5 | 0.2% | Mar 4, 2024 | An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious,... |
| CVE-2023-41827 | MEDIUM | 5.1 | 0.2% | Mar 4, 2024 | An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, loca... |
| CVE-2023-38360 | MEDIUM | 6.1 | 0.3% | Mar 4, 2024 | IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java... |
| CVE-2023-5451 | MEDIUM | 6.1 | 0.3% | Mar 4, 2024 | Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Ma... |
| CVE-2023-38362 | MEDIUM | 5.3 | 0.5% | Mar 4, 2024 | IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTT... |
| CVE-2023-33090 | MEDIUM | 5.5 | 0.1% | Mar 4, 2024 | Transient DOS while processing channel information for speaker protection v2 module in ADSP. |
| CVE-2023-33078 | MEDIUM | 5.5 | 0.1% | Mar 4, 2024 | Information Disclosure while processing IOCTL request in FastRPC. |
| CVE-2023-4479 | MEDIUM | 5.4 | 0.4% | Mar 4, 2024 | Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stor... |
| CVE-2023-49602 | MEDIUM | 5.5 | 0.1% | Mar 4, 2024 | in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion. |
| CVE-2023-25176 | MEDIUM | 5.5 | 0.1% | Mar 4, 2024 | in OpenHarmony v3.2.4 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now