2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28598 | MEDIUM | 6.5 | 0.5% | Jun 13, 2023 | Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malic... |
| CVE-2023-28303 | LOW | 3.3 | 2.0% | Jun 13, 2023 | Windows Snipping Tool Information Disclosure Vulnerability |
| CVE-2023-27837 | CRITICAL | 9.8 | 2.4% | Jun 13, 2023 | TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key par... |
| CVE-2023-20867 | LOW | 3.9 | 13.6% | Jun 13, 2023 | A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the con... |
| CVE-2023-33695 | HIGH | 7.1 | 0.2% | Jun 13, 2023 | Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile()... |
| CVE-2023-33621 | MEDIUM | 5.9 | 1.0% | Jun 13, 2023 | GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server ... |
| CVE-2023-27624 | MEDIUM | 4.8 | 0.6% | Jun 13, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcelotorres Redirect After Login plugin <= 0.1.9 ver... |
| CVE-2023-25978 | MEDIUM | 4.8 | 0.4% | Jun 13, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nate Reist Protected Posts Logout Button plugin <= 1.4... |
| CVE-2023-35064 | CRITICAL | 9.8 | 0.7% | Jun 13, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile... |
| CVE-2023-33568 | HIGH | 7.5 | 14.9% | Jun 13, 2023 | An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's... |
| CVE-2023-28620 | MEDIUM | 4.8 | 0.4% | Jun 13, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cyberus Labs Cyberus Key plugin <= 1.0 versions. |
| CVE-2023-26538 | MEDIUM | 4.8 | 0.4% | Jun 13, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kamyabsoft Chat Bee plugin <= 1.1.0 versions. |
| CVE-2023-26528 | MEDIUM | 4.8 | 0.4% | Jun 13, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in jinit9906 Shipyaari Shipping Management plugin <= 1.0 ... |
| CVE-2023-25964 | MEDIUM | 4.8 | 0.4% | Jun 13, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Noah Hearle, Design Extreme We’re Open! plugin <= 1.46... |
| CVE-2023-23831 | MEDIUM | 5.4 | 0.4% | Jun 13, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Rating-Widget Rating-Widget: Star Review System ... |
| CVE-2023-3050 | CRITICAL | 9.8 | 1.3% | Jun 13, 2023 | Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allow... |
| CVE-2023-3049 | CRITICAL | 9.8 | 3.7% | Jun 13, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection. This issue affe... |
| CVE-2023-3048 | CRITICAL | 9.8 | 1.3% | Jun 13, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authenticati... |
| CVE-2023-3047 | CRITICAL | 9.8 | 1.7% | Jun 13, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allow... |
| CVE-2023-2807 | CRITICAL | 9.8 | 0.6% | Jun 13, 2023 | Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated a... |
| CVE-2023-3218 | MEDIUM | 4.4 | 0.5% | Jun 13, 2023 | Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5. |
| CVE-2023-32548 | HIGH | 8.1 | 1.1% | Jun 13, 2023 | OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-... |
| CVE-2023-32546 | MEDIUM | 4.4 | 0.3% | Jun 13, 2023 | Code injection vulnerability exists in Chatwork Desktop Application (Mac) 2.6.43 and earlier. If this vulnerability is e... |
| CVE-2023-31198 | HIGH | 7.2 | 1.5% | Jun 13, 2023 | OS command injection vulnerability exists in Wi-Fi AP UNIT allows. If this vulnerability is exploited, a remote authenti... |
| CVE-2023-31196 | HIGH | 7.5 | 0.8% | Jun 13, 2023 | Missing authentication for critical function in Wi-Fi AP UNIT allows a remote unauthenticated attacker to obtain sensiti... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now