2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2903 | MEDIUM | 6.5 | 0.7% | May 25, 2023 | A vulnerability classified as problematic has been found in NFine Rapid Development Platform 20230511. This affects an u... |
| CVE-2023-31147 | MEDIUM | 6.5 | 0.9% | May 25, 2023 | c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to g... |
| CVE-2023-31130 | MEDIUM | 6.4 | 0.3% | May 25, 2023 | c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 ad... |
| CVE-2023-31124 | LOW | 3.7 | 0.9% | May 25, 2023 | c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RAND... |
| CVE-2023-2902 | MEDIUM | 6.5 | 0.7% | May 25, 2023 | A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by th... |
| CVE-2023-2901 | MEDIUM | 6.5 | 0.7% | May 25, 2023 | A vulnerability was found in NFine Rapid Development Platform 20230511. It has been declared as problematic. Affected by... |
| CVE-2023-2804 | MEDIUM | 6.5 | 1.2% | May 25, 2023 | A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrge... |
| CVE-2023-2900 | HIGH | 7.5 | 0.7% | May 25, 2023 | A vulnerability was found in NFine Rapid Development Platform 20230511. It has been classified as problematic. Affected ... |
| CVE-2023-33280 | CRITICAL | 9.8 | 0.6% | May 25, 2023 | In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be execut... |
| CVE-2023-33279 | CRITICAL | 9.8 | 0.6% | May 25, 2023 | In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed w... |
| CVE-2023-33278 | CRITICAL | 9.8 | 0.6% | May 25, 2023 | In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a... |
| CVE-2023-33263 | HIGH | 7.5 | 0.9% | May 25, 2023 | In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WF... |
| CVE-2023-2255 | MEDIUM | 5.3 | 2.2% | May 25, 2023 | Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a docum... |
| CVE-2023-25439 | MEDIUM | 6.1 | 2.2% | May 25, 2023 | Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitr... |
| CVE-2023-0950 | HIGH | 7.8 | 0.3% | May 25, 2023 | Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice all... |
| CVE-2023-26216 | HIGH | 7.2 | 0.8% | May 25, 2023 | The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an att... |
| CVE-2023-26215 | MEDIUM | 6.5 | 0.7% | May 25, 2023 | The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with lo... |
| CVE-2023-30851 | MEDIUM | 5.3 | 0.7% | May 25, 2023 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users... |
| CVE-2023-30615 | MEDIUM | 5.4 | 0.4% | May 25, 2023 | Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations.... |
| CVE-2023-33751 | MEDIUM | 5.4 | 0.4% | May 25, 2023 | A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or H... |
| CVE-2023-33750 | MEDIUM | 5.4 | 0.4% | May 25, 2023 | A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or H... |
| CVE-2023-32694 | MEDIUM | 5.4 | 0.3% | May 25, 2023 | Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing ... |
| CVE-2023-33356 | MEDIUM | 5.4 | 0.4% | May 25, 2023 | IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2023-33355 | HIGH | 7.5 | 0.6% | May 25, 2023 | IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitiv... |
| CVE-2023-2851 | CRITICAL | 9.8 | 0.7% | May 25, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now