2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30253 | HIGH | 8.8 | 79.3% | May 29, 2023 | Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instea... |
| CVE-2023-30571 | MEDIUM | 5.3 | 0.2% | May 29, 2023 | Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write... |
| CVE-2023-27613 | MEDIUM | 6.1 | 0.4% | May 29, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MonitorClick Forms Ada – Form Builder plugin <= 1.0 versio... |
| CVE-2023-23699 | MEDIUM | 5.4 | 0.4% | May 29, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Reynolds Progress Bar plugin <= 2.2.1 vers... |
| CVE-2023-2962 | CRITICAL | 9.8 | 0.7% | May 29, 2023 | A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. Affec... |
| CVE-2023-2808 | MEDIUM | 5.3 | 0.4% | May 29, 2023 | Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlin... |
| CVE-2023-2955 | CRITICAL | 9.8 | 0.8% | May 29, 2023 | A vulnerability, which was classified as critical, was found in SourceCodester Students Online Internship Timesheet Syst... |
| CVE-2023-2954 | MEDIUM | 5.4 | 0.4% | May 29, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master. |
| CVE-2023-24605 | MEDIUM | 4.2 | 0.4% | May 29, 2023 | OX App Suite before backend 7.10.6-rev37 does not enforce 2FA for all endpoints, e.g., reading from a drive, reading con... |
| CVE-2023-24604 | MEDIUM | 4.3 | 0.7% | May 29, 2023 | OX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g., potentially allowing... |
| CVE-2023-24603 | MEDIUM | 6.5 | 0.8% | May 29, 2023 | OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a craft... |
| CVE-2023-24602 | MEDIUM | 6.1 | 0.4% | May 29, 2023 | OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title. |
| CVE-2023-24601 | MEDIUM | 6.1 | 0.4% | May 29, 2023 | OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree. |
| CVE-2023-24600 | MEDIUM | 4.3 | 0.5% | May 29, 2023 | OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via... |
| CVE-2023-24599 | MEDIUM | 4.3 | 0.5% | May 29, 2023 | OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via co... |
| CVE-2023-24598 | MEDIUM | 4.3 | 0.5% | May 29, 2023 | OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial di... |
| CVE-2023-24597 | MEDIUM | 5.3 | 0.5% | May 29, 2023 | OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resour... |
| CVE-2023-29079 | — | — | — | May 29, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-29078 | — | — | — | May 29, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-28153 | MEDIUM | 6.4 | 0.5% | May 29, 2023 | An issue was discovered in the Kiddoware Kids Place Parental Control application before 3.8.50 for Android. The child ca... |
| CVE-2023-31874 | HIGH | 8.8 | 4.9% | May 29, 2023 | Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_pro... |
| CVE-2023-30570 | HIGH | 7.5 | 1.2% | May 29, 2023 | pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticat... |
| CVE-2023-30350 | HIGH | 8.8 | 5.3% | May 29, 2023 | FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin ... |
| CVE-2023-29380 | HIGH | 7.5 | 1.8% | May 29, 2023 | Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames. |
| CVE-2023-32763 | HIGH | 7.5 | 1.3% | May 28, 2023 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file wi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now