2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5611 | MEDIUM | 5.3 | 0.3% | Nov 27, 2023 | The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting a... |
| CVE-2023-5560 | MEDIUM | 6.1 | 0.5% | Nov 27, 2023 | The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputti... |
| CVE-2023-5525 | MEDIUM | 4.3 | 0.5% | Nov 27, 2023 | The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` A... |
| CVE-2023-5325 | MEDIUM | 6.1 | 0.5% | Nov 27, 2023 | The Woocommerce Vietnam Checkout WordPress plugin before 2.0.6 does not escape the custom shipping phone field no the ch... |
| CVE-2023-5209 | MEDIUM | 4.8 | 0.5% | Nov 27, 2023 | The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its... |
| CVE-2023-4642 | MEDIUM | 5.9 | 0.4% | Nov 27, 2023 | The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple ... |
| CVE-2023-4514 | MEDIUM | 5.4 | 0.4% | Nov 27, 2023 | The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes befo... |
| CVE-2023-4297 | MEDIUM | 4.3 | 0.6% | Nov 27, 2023 | The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing ... |
| CVE-2023-4252 | MEDIUM | 5.3 | 0.5% | Nov 27, 2023 | The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attack... |
| CVE-2023-49028 | MEDIUM | 5.4 | 0.8% | Nov 27, 2023 | Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitra... |
| CVE-2023-2707 | MEDIUM | 4.8 | 0.4% | Nov 27, 2023 | The gAppointments WordPress plugin through 1.9.5.1 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2023-49029 | MEDIUM | 6.1 | 0.9% | Nov 27, 2023 | Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitra... |
| CVE-2023-6287 | MEDIUM | 5.5 | 0.2% | Nov 27, 2023 | Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords... |
| CVE-2023-5871 | MEDIUM | 5.3 | 0.9% | Nov 27, 2023 | A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such a... |
| CVE-2023-43701 | MEDIUM | 5.4 | 1.0% | Nov 27, 2023 | Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious acto... |
| CVE-2023-42501 | MEDIUM | 4.3 | 0.9% | Nov 27, 2023 | Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and ... |
| CVE-2023-6202 | MEDIUM | 4.3 | 0.4% | Nov 27, 2023 | Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker w... |
| CVE-2023-48369 | MEDIUM | 5.3 | 0.6% | Nov 27, 2023 | Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to differe... |
| CVE-2023-47168 | MEDIUM | 6.1 | 0.4% | Nov 27, 2023 | Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user cli... |
| CVE-2023-45223 | MEDIUM | 4.3 | 0.5% | Nov 27, 2023 | Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a me... |
| CVE-2023-43754 | MEDIUM | 4.3 | 0.5% | Nov 27, 2023 | Mattermost fails to check whether the “Allow users to view archived channels” setting is enabled during permalink prev... |
| CVE-2023-35075 | MEDIUM | 5.4 | 0.4% | Nov 27, 2023 | Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowi... |
| CVE-2023-47865 | MEDIUM | 4.3 | 0.4% | Nov 27, 2023 | Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. ... |
| CVE-2023-25632 | MEDIUM | 5.5 | 0.2% | Nov 27, 2023 | The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open ... |
| CVE-2023-6313 | MEDIUM | 6.1 | 0.6% | Nov 27, 2023 | A vulnerability was found in SourceCodester URL Shortener 1.0. It has been declared as problematic. Affected by this vul... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now