2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5096 | MEDIUM | 5.4 | 0.4% | Nov 22, 2023 | The HTML filter and csv-file search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '... |
| CVE-2023-5048 | MEDIUM | 5.4 | 0.4% | Nov 22, 2023 | The WDContactFormBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Contact_Form_Builder... |
| CVE-2023-4726 | MEDIUM | 4.8 | 0.4% | Nov 22, 2023 | The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions ... |
| CVE-2023-4686 | MEDIUM | 4.3 | 0.5% | Nov 22, 2023 | The WP Customer Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and incl... |
| CVE-2023-48705 | MEDIUM | 5.4 | 0.5% | Nov 22, 2023 | Nautobot is a Network Source of Truth and Network Automation Platform built as a web application All users of Nautobot v... |
| CVE-2023-2448 | MEDIUM | 5.3 | 0.9% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '... |
| CVE-2023-2438 | MEDIUM | 6.1 | 0.2% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. Th... |
| CVE-2023-47380 | MEDIUM | 6.1 | 0.7% | Nov 22, 2023 | Admidio v4.2.12 and below is vulnerable to Cross Site Scripting (XSS). |
| CVE-2023-6253 | MEDIUM | 6 | 0.3% | Nov 22, 2023 | A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to re... |
| CVE-2023-3103 | MEDIUM | 5.9 | 0.6% | Nov 22, 2023 | Authentication bypass vulnerability, the exploitation of which could allow a local attacker to perform a Man-in-the-Midd... |
| CVE-2023-6189 | MEDIUM | 5.3 | 0.5% | Nov 22, 2023 | Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and... |
| CVE-2023-6011 | MEDIUM | 5.4 | 0.4% | Nov 22, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DECE Software Geod... |
| CVE-2023-2447 | MEDIUM | 6.1 | 0.2% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th... |
| CVE-2023-2446 | MEDIUM | 6.5 | 0.8% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versio... |
| CVE-2023-47393 | MEDIUM | 5.3 | 0.5% | Nov 22, 2023 | An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the maintenance orders of othe... |
| CVE-2023-47392 | MEDIUM | 5.3 | 0.5% | Nov 22, 2023 | An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via s... |
| CVE-2023-41146 | MEDIUM | 4.3 | 0.5% | Nov 22, 2023 | Autodesk Customer Support Portal allows cases created by users under an account to see cases created by other users on t... |
| CVE-2023-41145 | MEDIUM | 5.3 | 0.5% | Nov 22, 2023 | Autodesk users who no longer have an active license for an account can still access cases for that account. |
| CVE-2023-48701 | MEDIUM | 6.1 | 0.7% | Nov 21, 2023 | Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML file... |
| CVE-2023-48700 | MEDIUM | 6.5 | 0.4% | Nov 21, 2023 | The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new ... |
| CVE-2023-48305 | MEDIUM | 4.4 | 0.2% | Nov 21, 2023 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio... |
| CVE-2023-49104 | MEDIUM | 6.1 | 0.6% | Nov 21, 2023 | An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able ... |
| CVE-2023-48304 | MEDIUM | 4.3 | 0.6% | Nov 21, 2023 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio... |
| CVE-2023-48302 | MEDIUM | 5.4 | 0.6% | Nov 21, 2023 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio... |
| CVE-2023-48301 | MEDIUM | 5.4 | 0.6% | Nov 21, 2023 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now