2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-52555 | MEDIUM | 6.1 | 0.2% | Mar 1, 2024 | In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection. |
| CVE-2023-50312 | MEDIUM | 6.5 | 0.6% | Mar 1, 2024 | IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbo... |
| CVE-2023-38366 | MEDIUM | 5.3 | 0.8% | Mar 1, 2024 | IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse director... |
| CVE-2023-50324 | MEDIUM | 5.3 | 0.4% | Mar 1, 2024 | IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an a... |
| CVE-2023-50305 | MEDIUM | 5.1 | 0.2% | Mar 1, 2024 | IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by defaul... |
| CVE-2023-28949 | MEDIUM | 6.5 | 0.2% | Mar 1, 2024 | IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an a... |
| CVE-2023-28525 | MEDIUM | 4.8 | 0.3% | Mar 1, 2024 | IBM Engineering Requirements Management 9.7.2.7 is vulnerable to cross-site scripting. This vulnerability allows users t... |
| CVE-2023-52485 | MEDIUM | 5.5 | 0.2% | Feb 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before sending a comman... |
| CVE-2023-52484 | MEDIUM | 5.5 | 0.2% | Feb 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Fix soft lockup triggered by arm... |
| CVE-2023-52481 | MEDIUM | 4.7 | 0.6% | Feb 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Add Cortex-A520 speculative unprivil... |
| CVE-2023-52478 | MEDIUM | 4.7 | 0.2% | Feb 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Fix kernel crash on receiver U... |
| CVE-2023-52477 | MEDIUM | 5.5 | 0.2% | Feb 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb: hub: Guard against accesses to uninitialized B... |
| CVE-2023-52476 | MEDIUM | 5.5 | 0.2% | Feb 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: perf/x86/lbr: Filter vsyscall addresses We found t... |
| CVE-2023-50905 | MEDIUM | 6.1 | 0.3% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activ... |
| CVE-2023-1841 | MEDIUM | 4.8 | 0.4% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Honeywell MPA2 Acc... |
| CVE-2023-51802 | MEDIUM | 6.1 | 0.6% | Feb 29, 2024 | Cross Site Scripting (XSS) vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execu... |
| CVE-2023-51800 | MEDIUM | 5.4 | 0.6% | Feb 29, 2024 | Cross Site Scripting (XSS) vulnerability in School Fees Management System v.1.0 allows a remote attacker to execute arbi... |
| CVE-2023-38367 | MEDIUM | 6.5 | 0.3% | Feb 29, 2024 | IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19... |
| CVE-2023-27545 | MEDIUM | 5.5 | 0.2% | Feb 29, 2024 | IBM Watson CloudPak for Data Data Stores information disclosure 4.6.0 allows web pages to be stored locally which can be... |
| CVE-2023-7207 | MEDIUM | 4.9 | 0.9% | Feb 29, 2024 | Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches whic... |
| CVE-2023-7108 | MEDIUM | 6.1 | 0.8% | Feb 29, 2024 | A vulnerability classified as problematic has been found in code-projects E-Commerce Website 1.0. This affects an unknow... |
| CVE-2023-6923 | MEDIUM | 6.1 | 0.5% | Feb 29, 2024 | The Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Scri... |
| CVE-2023-6806 | MEDIUM | 5.4 | 0.4% | Feb 29, 2024 | The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields i... |
| CVE-2023-6565 | MEDIUM | 5.9 | 0.6% | Feb 29, 2024 | The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2023-6247 | MEDIUM | 6.5 | 0.8% | Feb 29, 2024 | The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which woul... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now