2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34223 | MEDIUM | 5.3 | 1.3% | May 31, 2023 | In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some c... |
| CVE-2023-34222 | MEDIUM | 6.1 | 1.0% | May 31, 2023 | In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible |
| CVE-2023-34221 | MEDIUM | 5.4 | 1.0% | May 31, 2023 | In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible |
| CVE-2023-34220 | MEDIUM | 5.4 | 61.2% | May 31, 2023 | In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible |
| CVE-2023-34219 | MEDIUM | 4.3 | 0.4% | May 31, 2023 | In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Bu... |
| CVE-2023-34218 | CRITICAL | 9.8 | 0.6% | May 31, 2023 | In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible |
| CVE-2023-31548 | MEDIUM | 5.4 | 1.2% | May 31, 2023 | A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attac... |
| CVE-2023-26842 | MEDIUM | 5.4 | 1.4% | May 31, 2023 | A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web scr... |
| CVE-2023-3009 | MEDIUM | 5.4 | 0.7% | May 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. |
| CVE-2023-33736 | MEDIUM | 5.4 | 0.4% | May 31, 2023 | A stored cross-site scripting (XSS) vulnerability in Dcat-Admin v2.1.3-beta allows attackers to execute arbitrary web sc... |
| CVE-2023-33509 | CRITICAL | 9.8 | 0.8% | May 31, 2023 | KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection. |
| CVE-2023-33508 | CRITICAL | 9.8 | 1.4% | May 31, 2023 | KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE). |
| CVE-2023-33507 | HIGH | 7.5 | 0.7% | May 31, 2023 | KramerAV VIA GO² < 4.0.1.1326 is vulnerable to Unauthenticated arbitrary file read. |
| CVE-2023-33487 | CRITICAL | 9.8 | 1.4% | May 31, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagn... |
| CVE-2023-33486 | CRITICAL | 9.8 | 1.4% | May 31, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpMode... |
| CVE-2023-33485 | HIGH | 8.8 | 1.1% | May 31, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via par... |
| CVE-2023-3008 | CRITICAL | 9.8 | 0.8% | May 31, 2023 | A vulnerability classified as critical has been found in ningzichun Student Management System 1.0. This affects an unkno... |
| CVE-2023-3007 | CRITICAL | 9.8 | 1.0% | May 31, 2023 | A vulnerability was found in ningzichun Student Management System 1.0. It has been rated as critical. Affected by this i... |
| CVE-2023-30285 | HIGH | 7.5 | 0.8% | May 31, 2023 | An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a us... |
| CVE-2023-2909 | CRITICAL | 10 | 0.7% | May 31, 2023 | EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory st... |
| CVE-2023-3005 | MEDIUM | 6.1 | 0.6% | May 31, 2023 | A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management... |
| CVE-2023-3004 | CRITICAL | 9.8 | 0.8% | May 31, 2023 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple Chat System 1.0. Affected by ... |
| CVE-2023-3003 | CRITICAL | 9.8 | 0.8% | May 31, 2023 | A vulnerability classified as critical was found in SourceCodester Train Station Ticketing System 1.0. Affected by this ... |
| CVE-2023-2749 | HIGH | 7.5 | 0.5% | May 31, 2023 | Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability... |
| CVE-2023-2304 | MEDIUM | 5.4 | 0.7% | May 31, 2023 | The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_favorites' shortcode in ve... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now