2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25792 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in XiaoMac WP Open Social plugin <= 5.0 versions. |
| CVE-2023-25789 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tapfiliate plugin <= 3.0.12 versions. |
| CVE-2023-25787 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wbolt team WP资源下载管理 plugin <= 1.3.9 versions. |
| CVE-2023-25786 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Thom Stark Eyes Only: User Access Shortcode plugin <= ... |
| CVE-2023-25784 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bon Plan Gratos Sticky Ad Bar plugin <= 1.3.1 versions... |
| CVE-2023-25783 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Moss FireCask Like & Share Button plugin <= 1.1.5... |
| CVE-2023-23790 | HIGH | 8.8 | 0.3% | May 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= ... |
| CVE-2023-28070 | HIGH | 7.8 | 0.1% | May 3, 2023 | Alienware Command Center Application, versions 5.5.43.0 and prior, contain an improper access control vulnerability. A ... |
| CVE-2023-22691 | HIGH | 8.8 | 0.3% | May 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscriptio... |
| CVE-2023-29839 | MEDIUM | 5.4 | 0.7% | May 3, 2023 | A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows ar... |
| CVE-2023-2468 | MEDIUM | 4.3 | 0.8% | May 3, 2023 | Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who h... |
| CVE-2023-2467 | MEDIUM | 4.3 | 0.8% | May 3, 2023 | Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to ... |
| CVE-2023-2466 | MEDIUM | 4.3 | 0.8% | May 3, 2023 | Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the c... |
| CVE-2023-2465 | MEDIUM | 4.3 | 1.0% | May 3, 2023 | Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-ori... |
| CVE-2023-2464 | MEDIUM | 4.3 | 0.6% | May 3, 2023 | Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinc... |
| CVE-2023-2463 | MEDIUM | 4.3 | 0.9% | May 3, 2023 | Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote att... |
| CVE-2023-2462 | MEDIUM | 4.3 | 0.8% | May 3, 2023 | Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate m... |
| CVE-2023-2461 | HIGH | 8.8 | 0.8% | May 3, 2023 | Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced ... |
| CVE-2023-2460 | HIGH | 7.1 | 0.7% | May 3, 2023 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who... |
| CVE-2023-2459 | MEDIUM | 6.5 | 1.0% | May 3, 2023 | Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass perm... |
| CVE-2023-27892 | MEDIUM | 5.7 | 0.5% | May 2, 2023 | Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.7.0 allow a global buffer overflo... |
| CVE-2023-26268 | MEDIUM | 5.3 | 1.4% | May 2, 2023 | Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environm... |
| CVE-2023-31435 | HIGH | 8.1 | 0.7% | May 2, 2023 | Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire p... |
| CVE-2023-31434 | MEDIUM | 5.4 | 0.5% | May 2, 2023 | The parameters nutzer_titel, nutzer_vn, and nutzer_nn in the user profile, and langID and ONLINEID in direct links, in e... |
| CVE-2023-31433 | HIGH | 8.8 | 0.9% | May 2, 2023 | A SQL injection issue in Logbuch in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allows authenticated atta... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now