2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49810 | MEDIUM | 6.5 | 0.7% | Jan 10, 2024 | A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev maste... |
| CVE-2023-48730 | MEDIUM | 5.4 | 0.6% | Jan 10, 2024 | A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo de... |
| CVE-2023-48728 | MEDIUM | 6.1 | 2.3% | Jan 10, 2024 | A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.... |
| CVE-2023-47861 | MEDIUM | 5.4 | 0.8% | Jan 10, 2024 | A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and... |
| CVE-2023-47171 | MEDIUM | 6.5 | 1.1% | Jan 10, 2024 | An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo... |
| CVE-2023-6158 | MEDIUM | 6.5 | 0.6% | Jan 10, 2024 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2023-5455 | MEDIUM | 6.5 | 0.6% | Jan 10, 2024 | A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This f... |
| CVE-2023-48256 | MEDIUM | 6.3 | 0.3% | Jan 10, 2024 | The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies ... |
| CVE-2023-48255 | MEDIUM | 6.1 | 0.5% | Jan 10, 2024 | The vulnerability allows an unauthenticated remote attacker to send malicious network requests containing arbitrary clie... |
| CVE-2023-48254 | MEDIUM | 6.1 | 0.3% | Jan 10, 2024 | The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s ses... |
| CVE-2023-48249 | MEDIUM | 6.5 | 0.8% | Jan 10, 2024 | The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the... |
| CVE-2023-48248 | MEDIUM | 5.4 | 0.4% | Jan 10, 2024 | The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary... |
| CVE-2023-48246 | MEDIUM | 6.5 | 0.8% | Jan 10, 2024 | The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of t... |
| CVE-2023-48244 | MEDIUM | 6.1 | 0.3% | Jan 10, 2024 | The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s ses... |
| CVE-2023-48242 | MEDIUM | 6.5 | 0.8% | Jan 10, 2024 | The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under t... |
| CVE-2023-51252 | MEDIUM | 5.4 | 0.3% | Jan 10, 2024 | PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is ... |
| CVE-2023-50120 | MEDIUM | 5.5 | 0.2% | Jan 10, 2024 | MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc... |
| CVE-2023-49394 | MEDIUM | 6.1 | 0.4% | Jan 10, 2024 | Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly. |
| CVE-2023-41603 | MEDIUM | 5.3 | 0.5% | Jan 10, 2024 | D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to... |
| CVE-2023-41781 | MEDIUM | 6.1 | 0.3% | Jan 10, 2024 | There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interfac... |
| CVE-2023-47997 | MEDIUM | 6.5 | 0.9% | Jan 10, 2024 | An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allo... |
| CVE-2023-47996 | MEDIUM | 6.5 | 0.6% | Jan 9, 2024 | An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attackers to obtain informa... |
| CVE-2023-47995 | MEDIUM | 6.5 | 0.7% | Jan 9, 2024 | Memory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0... |
| CVE-2023-47993 | MEDIUM | 6.5 | 0.6% | Jan 9, 2024 | A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-o... |
| CVE-2023-5770 | MEDIUM | 5.4 | 0.3% | Jan 9, 2024 | Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated att... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now