2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-50358 | MEDIUM | 5.8 | 12.8% | Feb 13, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2023-52060 | MEDIUM | 4.3 | 0.3% | Feb 13, 2024 | A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via... |
| CVE-2023-52059 | MEDIUM | 5.4 | 0.4% | Feb 13, 2024 | A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML ... |
| CVE-2023-49339 | MEDIUM | 6.5 | 0.6% | Feb 13, 2024 | Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/s... |
| CVE-2023-52430 | MEDIUM | 6.1 | 0.4% | Feb 12, 2024 | The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload ... |
| CVE-2023-28018 | MEDIUM | 6.5 | 0.3% | Feb 12, 2024 | HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a special... |
| CVE-2023-7233 | MEDIUM | 4.8 | 0.5% | Feb 12, 2024 | The GigPress WordPress plugin through 2.3.29 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2023-6591 | MEDIUM | 4.8 | 0.5% | Feb 12, 2024 | The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2023-6501 | MEDIUM | 4.3 | 0.2% | Feb 12, 2024 | The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could... |
| CVE-2023-6499 | MEDIUM | 5.4 | 0.2% | Feb 12, 2024 | The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well... |
| CVE-2023-6082 | MEDIUM | 5.4 | 0.4% | Feb 12, 2024 | The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-6081 | MEDIUM | 5.4 | 0.4% | Feb 12, 2024 | The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-6681 | MEDIUM | 5.3 | 0.9% | Feb 12, 2024 | A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possib... |
| CVE-2023-41708 | MEDIUM | 5.4 | 0.5% | Feb 12, 2024 | References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app ... |
| CVE-2023-41707 | MEDIUM | 6.5 | 0.8% | Feb 12, 2024 | Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to ... |
| CVE-2023-41706 | MEDIUM | 6.5 | 0.8% | Feb 12, 2024 | Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource thre... |
| CVE-2023-41705 | MEDIUM | 6.5 | 0.8% | Feb 12, 2024 | Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to h... |
| CVE-2023-41704 | MEDIUM | 6.1 | 0.5% | Feb 12, 2024 | Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine... |
| CVE-2023-41703 | MEDIUM | 6.1 | 0.5% | Feb 12, 2024 | User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a use... |
| CVE-2023-51403 | MEDIUM | 5.4 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicdark Restaurant... |
| CVE-2023-51370 | MEDIUM | 4.8 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam WP Chat ... |
| CVE-2023-50875 | MEDIUM | 5.4 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei ... |
| CVE-2023-47526 | MEDIUM | 4.8 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team... |
| CVE-2023-52429 | MEDIUM | 5.5 | 0.2% | Feb 12, 2024 | dm_table_create in drivers/md/dm-table.c in the Linux kernel through 6.7.4 can attempt to (in alloc_targets) allocate mo... |
| CVE-2023-51493 | MEDIUM | 5.4 | 0.3% | Feb 10, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Howard Ehrenberg C... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now