2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-7124 | MEDIUM | 6.1 | 0.7% | Dec 28, 2023 | A vulnerability, which was classified as problematic, was found in code-projects E-Commerce Site 1.0. Affected is an unk... |
| CVE-2023-34829 | MEDIUM | 6.5 | 0.2% | Dec 28, 2023 | Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext. |
| CVE-2023-49003 | MEDIUM | 5.3 | 0.5% | Dec 27, 2023 | An issue in simplemobiletools Simple Dialer 5.18.1 allows an attacker to bypass intended access restrictions via interac... |
| CVE-2023-46918 | MEDIUM | 4.6 | 0.3% | Dec 27, 2023 | Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an... |
| CVE-2023-51079 | MEDIUM | 5.3 | 0.7% | Dec 27, 2023 | A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java c... |
| CVE-2023-51074 | MEDIUM | 5.3 | 0.7% | Dec 27, 2023 | json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method. |
| CVE-2023-46919 | MEDIUM | 6.3 | 0.1% | Dec 27, 2023 | Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) ... |
| CVE-2023-51443 | MEDIUM | 5.9 | 1.5% | Dec 27, 2023 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ... |
| CVE-2023-4641 | MEDIUM | 5.5 | 0.3% | Dec 27, 2023 | A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password ... |
| CVE-2023-49438 | MEDIUM | 6.1 | 1.1% | Dec 26, 2023 | An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspectin... |
| CVE-2023-48003 | MEDIUM | 6.1 | 0.5% | Dec 26, 2023 | An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redire... |
| CVE-2023-6268 | MEDIUM | 6.1 | 0.4% | Dec 26, 2023 | The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting... |
| CVE-2023-6166 | MEDIUM | 6.1 | 0.4% | Dec 26, 2023 | The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, lead... |
| CVE-2023-6155 | MEDIUM | 5.3 | 0.6% | Dec 26, 2023 | The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX acti... |
| CVE-2023-5980 | MEDIUM | 4.8 | 0.4% | Dec 26, 2023 | The BSK Forms Blacklist WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow... |
| CVE-2023-5672 | MEDIUM | 6.5 | 0.7% | Dec 26, 2023 | The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to em... |
| CVE-2023-51363 | MEDIUM | 6.5 | 0.3% | Dec 26, 2023 | VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's ... |
| CVE-2023-50339 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v... |
| CVE-2023-50332 | MEDIUM | 6.5 | 0.4% | Dec 26, 2023 | Improper authorization vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.0.6... |
| CVE-2023-50294 | MEDIUM | 6.5 | 0.3% | Dec 26, 2023 | The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As ... |
| CVE-2023-50175 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page, the Markdown Settings (/admin/ma... |
| CVE-2023-49807 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability when processing the MathJax exists in GROWI versions prior to v6.0.0. If this ... |
| CVE-2023-49779 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability exists in the anchor tag of GROWI versions prior to v6.0.0. If this vulnerabil... |
| CVE-2023-49598 | MEDIUM | 5.4 | 0.3% | Dec 26, 2023 | Stored cross-site scripting vulnerability exists in the event handlers of the pre tags in GROWI versions prior to v6.0.0... |
| CVE-2023-49119 | MEDIUM | 5.4 | 0.4% | Dec 26, 2023 | Stored cross-site scripting vulnerability via the img tags exists in GROWI versions prior to v6.0.0. If this vulnerabili... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now