2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2947 | MEDIUM | 4.8 | 90.8% | May 27, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1. |
| CVE-2023-2946 | HIGH | 8.1 | 0.5% | May 27, 2023 | Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. |
| CVE-2023-2945 | MEDIUM | 5.4 | 0.4% | May 27, 2023 | Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1. |
| CVE-2023-2944 | MEDIUM | 5.4 | 0.4% | May 27, 2023 | Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. |
| CVE-2023-2943 | HIGH | 8.8 | 0.6% | May 27, 2023 | Code Injection in GitHub repository openemr/openemr prior to 7.0.1. |
| CVE-2023-2942 | HIGH | 8.1 | 0.8% | May 27, 2023 | Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1. |
| CVE-2023-32695 | HIGH | 7.5 | 1.1% | May 27, 2023 | socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol... |
| CVE-2023-2928 | HIGH | 8.8 | 51.4% | May 27, 2023 | A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is ... |
| CVE-2023-2927 | CRITICAL | 9.8 | 0.9% | May 27, 2023 | A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the f... |
| CVE-2023-2926 | MEDIUM | 6.5 | 0.9% | May 27, 2023 | A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of th... |
| CVE-2023-2925 | MEDIUM | 5.4 | 0.6% | May 27, 2023 | A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part... |
| CVE-2023-2924 | CRITICAL | 9.8 | 24.3% | May 27, 2023 | A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. Affected by this ... |
| CVE-2023-2923 | CRITICAL | 9.8 | 1.0% | May 27, 2023 | A vulnerability classified as critical was found in Tenda AC6 US_AC6V1.0BR_V15.03.05.19. Affected by this vulnerability ... |
| CVE-2023-2922 | MEDIUM | 6.1 | 0.6% | May 27, 2023 | A vulnerability classified as problematic has been found in SourceCodester Comment System 1.0. Affected is an unknown fu... |
| CVE-2023-33184 | MEDIUM | 5.3 | 0.5% | May 27, 2023 | Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the s... |
| CVE-2023-26129 | HIGH | 7.8 | 1.0% | May 27, 2023 | All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check'... |
| CVE-2023-26128 | HIGH | 7.8 | 1.2% | May 27, 2023 | All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or ... |
| CVE-2023-26127 | HIGH | 7.8 | 1.0% | May 27, 2023 | All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.e... |
| CVE-2023-33195 | MEDIUM | 6.1 | 0.7% | May 27, 2023 | Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This... |
| CVE-2023-33192 | HIGH | 7.5 | 0.7% | May 27, 2023 | ntpd-rs is an NTP implementation written in Rust. ntpd-rs does not validate the length of NTS cookies in received NTP pa... |
| CVE-2023-33188 | MEDIUM | 5.5 | 0.3% | May 27, 2023 | Omni-notes is an open source note-taking application for Android. The Omni-notes Android app had an insufficient path va... |
| CVE-2023-32688 | HIGH | 7.5 | 0.9% | May 27, 2023 | parse-server-push-adapter is the official Push Notification adapter for Parse Server. The Parse Server Push Adapter can ... |
| CVE-2023-32686 | MEDIUM | 5.4 | 0.4% | May 27, 2023 | Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to uplo... |
| CVE-2023-32325 | MEDIUM | 6.1 | 0.4% | May 27, 2023 | PostHog-js is a library to interface with the PostHog analytics tool. Versions prior to 1.57.2 have the potential for cr... |
| CVE-2023-33199 | MEDIUM | 5.3 | 0.7% | May 26, 2023 | Rekor's goals are to provide an immutable tamper resistant ledger of metadata generated within a software projects suppl... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now