2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47505 | MEDIUM | 5.4 | 25.3% | Nov 30, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elem... |
| CVE-2023-45050 | MEDIUM | 5.4 | 0.5% | Nov 30, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack... |
| CVE-2023-41136 | MEDIUM | 4.8 | 0.4% | Nov 30, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Laurence/OhMyBox.I... |
| CVE-2023-48743 | MEDIUM | 6.1 | 0.4% | Nov 30, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Menard Simply... |
| CVE-2023-48737 | MEDIUM | 4.8 | 0.4% | Nov 30, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PT Trijaya Digital... |
| CVE-2023-48336 | MEDIUM | 5.4 | 0.4% | Nov 30, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cybernetikz Easy S... |
| CVE-2023-49620 | MEDIUM | 6.5 | 1.1% | Nov 30, 2023 | Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (whi... |
| CVE-2023-49081 | MEDIUM | 5.3 | 0.9% | Nov 30, 2023 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for... |
| CVE-2023-49077 | MEDIUM | 6.1 | 0.4% | Nov 30, 2023 | Mailcow: dockerized is an open source groupware/email suite based on docker. A Cross-Site Scripting (XSS) vulnerability ... |
| CVE-2023-49076 | MEDIUM | 6.5 | 0.3% | Nov 30, 2023 | Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSR... |
| CVE-2023-5275 | MEDIUM | 4.7 | 0.3% | Nov 30, 2023 | Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-serv... |
| CVE-2023-5274 | MEDIUM | 4.7 | 0.3% | Nov 30, 2023 | Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-serv... |
| CVE-2023-49094 | MEDIUM | 4.3 | 0.7% | Nov 30, 2023 | Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker cou... |
| CVE-2023-5772 | MEDIUM | 4.3 | 0.3% | Nov 30, 2023 | The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2023-49082 | MEDIUM | 5.3 | 0.9% | Nov 29, 2023 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible fo... |
| CVE-2023-44383 | MEDIUM | 5.4 | 0.4% | Nov 29, 2023 | October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to... |
| CVE-2023-6217 | MEDIUM | 6.1 | 0.5% | Nov 29, 2023 | In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a refle... |
| CVE-2023-48882 | MEDIUM | 4.8 | 0.4% | Nov 29, 2023 | A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s... |
| CVE-2023-48881 | MEDIUM | 4.8 | 0.4% | Nov 29, 2023 | A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s... |
| CVE-2023-48880 | MEDIUM | 4.8 | 0.4% | Nov 29, 2023 | A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web s... |
| CVE-2023-49090 | MEDIUM | 6.1 | 0.6% | Nov 29, 2023 | CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-T... |
| CVE-2023-49674 | MEDIUM | 4.3 | 0.5% | Nov 29, 2023 | A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Over... |
| CVE-2023-49653 | MEDIUM | 6.5 | 0.6% | Nov 29, 2023 | Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers wit... |
| CVE-2023-6070 | MEDIUM | 4.3 | 0.2% | Nov 29, 2023 | A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user t... |
| CVE-2023-49092 | MEDIUM | 5.9 | 0.6% | Nov 28, 2023 | RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information abo... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now