2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-30253HIGH8.8Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instea...
CVE-2023-30571MEDIUM5.3Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write...
CVE-2023-27613MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MonitorClick Forms Ada – Form Builder plugin <= 1.0 versio...
CVE-2023-23699MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Reynolds Progress Bar plugin <= 2.2.1 vers...
CVE-2023-2962CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. Affec...
CVE-2023-2808MEDIUM5.3Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlin...
CVE-2023-2955CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Students Online Internship Timesheet Syst...
CVE-2023-2954MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.
CVE-2023-24605MEDIUM4.2OX App Suite before backend 7.10.6-rev37 does not enforce 2FA for all endpoints, e.g., reading from a drive, reading con...
CVE-2023-24604MEDIUM4.3OX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g., potentially allowing...
CVE-2023-24603MEDIUM6.5OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a craft...
CVE-2023-24602MEDIUM6.1OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.
CVE-2023-24601MEDIUM6.1OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
CVE-2023-24600MEDIUM4.3OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via...
CVE-2023-24599MEDIUM4.3OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via co...
CVE-2023-24598MEDIUM4.3OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial di...
CVE-2023-24597MEDIUM5.3OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resour...
CVE-2023-29079Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-29078Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-28153MEDIUM6.4An issue was discovered in the Kiddoware Kids Place Parental Control application before 3.8.50 for Android. The child ca...
CVE-2023-31874HIGH8.8Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_pro...
CVE-2023-30570HIGH7.5pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticat...
CVE-2023-30350HIGH8.8FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin ...
CVE-2023-29380HIGH7.5Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames.
CVE-2023-32763HIGH7.5An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file wi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now