2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-41905 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | NETSCOUT nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting (XSS) vulnerability by an authenticated use... |
| CVE-2023-41172 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4). |
| CVE-2023-41171 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4). |
| CVE-2023-41170 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability. |
| CVE-2023-41169 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 2 of 4). |
| CVE-2023-41168 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4). |
| CVE-2023-6588 | MEDIUM | 6.5 | 0.6% | Dec 7, 2023 | Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Wo... |
| CVE-2023-49493 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at ... |
| CVE-2023-49492 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parame... |
| CVE-2023-46974 | MEDIUM | 5.4 | 0.7% | Dec 7, 2023 | Cross Site Scripting vulnerability in Best Courier Management System v.1.000 allows a remote attacker to execute arbitra... |
| CVE-2023-47548 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Do... |
| CVE-2023-45762 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Michael Uno (miunosoft) Responsive Column Widgets.T... |
| CVE-2023-48325 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in PluginOps Landing Page Builder – Lead Page – Optin ... |
| CVE-2023-47779 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks. Integration for Constant Contact and Con... |
| CVE-2023-35909 | MEDIUM | 5.3 | 0.6% | Dec 7, 2023 | Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Buil... |
| CVE-2023-49746 | MEDIUM | 4.3 | 0.3% | Dec 7, 2023 | Server-Side Request Forgery (SSRF) vulnerability in Softaculous Team SpeedyCache – Cache, Optimization, Performance.This... |
| CVE-2023-46641 | MEDIUM | 5.4 | 0.3% | Dec 7, 2023 | Server-Side Request Forgery (SSRF) vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Me... |
| CVE-2023-41804 | MEDIUM | 5.4 | 0.3% | Dec 7, 2023 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver B... |
| CVE-2023-49225 | MEDIUM | 6.1 | 0.4% | Dec 7, 2023 | A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If t... |
| CVE-2023-48839 | MEDIUM | 5.4 | 0.4% | Dec 7, 2023 | Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_ap... |
| CVE-2023-48838 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code. |
| CVE-2023-48837 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code. |
| CVE-2023-48836 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_ke... |
| CVE-2023-48828 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_... |
| CVE-2023-48827 | MEDIUM | 5.4 | 0.5% | Dec 7, 2023 | Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now