LiveActive security incident?Get immediate response
CVE archive

2023 CVE Archive

Browse CVE records published in 2023 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 30600 matching CVEs · Page 16 of 612.

Unknown · CVSS Not scored

CVE-2023-40985: An issue was discovered in Webmin 2.100.

An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when any file is searched/replaced.

Published Sep 15, 2023 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2023-40932: A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attac...

A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.

Published Sep 19, 2023 · Updated Jul 9, 2026

Critical · CVSS 9.8

CVE-2023-39809: N.V.K.INTER CO., LTD.

N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php.

Published Aug 21, 2023 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2023-39808: N.V.K.INTER CO., LTD.

N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the vulnerability discoverer.

Published Aug 21, 2023 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2023-39807: N.V.K.INTER CO., LTD.

N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.

Published Aug 21, 2023 · Updated Jul 9, 2026