2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47786 | MEDIUM | 5.4 | 0.4% | Nov 22, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LayerSlider plugin... |
| CVE-2023-47773 | MEDIUM | 6.1 | 0.4% | Nov 22, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YAS Global Team Pe... |
| CVE-2023-47768 | MEDIUM | 6.1 | 0.4% | Nov 22, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson F... |
| CVE-2023-47767 | MEDIUM | 6.1 | 0.4% | Nov 22, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fla-shop.Com Inter... |
| CVE-2023-47766 | MEDIUM | 6.1 | 0.4% | Nov 22, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Reith Post St... |
| CVE-2023-47759 | MEDIUM | 4.8 | 0.4% | Nov 22, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premio Chaty chaty... |
| CVE-2023-30496 | MEDIUM | 6.1 | 0.4% | Nov 22, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MagePeople Team Wp... |
| CVE-2023-6264 | MEDIUM | 5.3 | 0.5% | Nov 22, 2023 | Information leak in Content-Security-Policy header in Devolutions Server 2023.3.7.0 allows an unauthenticated attacker t... |
| CVE-2023-25682 | MEDIUM | 5.5 | 0.2% | Nov 22, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sens... |
| CVE-2023-47755 | MEDIUM | 6.1 | 0.4% | Nov 22, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AazzTech WooCommer... |
| CVE-2023-47467 | MEDIUM | 6.5 | 1.1% | Nov 22, 2023 | Directory Traversal vulnerability in jeecg-boot v.3.6.0 allows a remote privileged attacker to obtain sensitive informat... |
| CVE-2023-47251 | MEDIUM | 6.5 | 1.7% | Nov 22, 2023 | In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the ... |
| CVE-2023-47014 | MEDIUM | 6.5 | 0.3% | Nov 22, 2023 | A Cross-Site Request Forgery (CSRF) vulnerability in Sourcecodester Sticky Notes App Using PHP with Source Code v.1.0 al... |
| CVE-2023-47316 | MEDIUM | 5.4 | 0.4% | Nov 22, 2023 | Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control. The Web panel allows users to gain access to po... |
| CVE-2023-47314 | MEDIUM | 5.4 | 0.4% | Nov 22, 2023 | Headwind MDM Web panel 5.22.1 is vulnerable to cross-site scripting (XSS). The file upload function allows APK and arbit... |
| CVE-2023-47313 | MEDIUM | 5.4 | 0.8% | Nov 22, 2023 | Headwind MDM Web panel 5.22.1 is vulnerable to Directory Traversal. The application uses an API call to move the uploade... |
| CVE-2023-47312 | MEDIUM | 6.5 | 0.4% | Nov 22, 2023 | Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to Login Credential Leakage via Audit Entrie... |
| CVE-2023-43082 | MEDIUM | 5.9 | 0.3% | Nov 22, 2023 | Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a ce... |
| CVE-2023-20241 | MEDIUM | 5.5 | 0.2% | Nov 22, 2023 | Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an aut... |
| CVE-2023-20240 | MEDIUM | 5.5 | 0.2% | Nov 22, 2023 | Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an aut... |
| CVE-2023-20084 | MEDIUM | 4.4 | 0.2% | Nov 22, 2023 | A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attack... |
| CVE-2023-6164 | MEDIUM | 4.8 | 0.4% | Nov 22, 2023 | The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS In... |
| CVE-2023-6160 | MEDIUM | 6.7 | 0.8% | Nov 22, 2023 | The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions... |
| CVE-2023-6008 | MEDIUM | 4.3 | 0.2% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th... |
| CVE-2023-6007 | MEDIUM | 6.5 | 0.3% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now