2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46471 | MEDIUM | 5.4 | 0.6% | Nov 20, 2023 | Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbi... |
| CVE-2023-46470 | MEDIUM | 5.4 | 0.6% | Nov 20, 2023 | Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbi... |
| CVE-2023-47417 | MEDIUM | 6.1 | 0.5% | Nov 20, 2023 | Cross Site Scripting (XSS) vulnerability in the component /shells/embedder.html of DZSlides after v2011.07.25 allows att... |
| CVE-2023-5799 | MEDIUM | 5.4 | 0.5% | Nov 20, 2023 | The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing ... |
| CVE-2023-5651 | MEDIUM | 5.4 | 0.3% | Nov 20, 2023 | The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensu... |
| CVE-2023-5610 | MEDIUM | 5.4 | 0.4% | Nov 20, 2023 | The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user ... |
| CVE-2023-5609 | MEDIUM | 6.1 | 0.4% | Nov 20, 2023 | The Seraphinite Accelerator WordPress plugin before 2.2.29 does not sanitise and escape a parameter before outputting it... |
| CVE-2023-5509 | MEDIUM | 5.4 | 0.5% | Nov 20, 2023 | The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in use... |
| CVE-2023-5343 | MEDIUM | 4.8 | 0.5% | Nov 20, 2023 | The Popup box WordPress plugin before 3.7.9 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-5140 | MEDIUM | 6.1 | 0.4% | Nov 20, 2023 | The Bonus for Woo WordPress plugin before 5.8.3 does not sanitise and escape some parameters before outputting them back... |
| CVE-2023-5119 | MEDIUM | 4.8 | 0.5% | Nov 20, 2023 | The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission s... |
| CVE-2023-4970 | MEDIUM | 4.8 | 0.4% | Nov 20, 2023 | The PubyDoc WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2023-4808 | MEDIUM | 4.8 | 0.4% | Nov 20, 2023 | The WP Post Popup WordPress plugin through 3.7.3 does not sanitise and escape some of its inputs, which could allow high... |
| CVE-2023-4799 | MEDIUM | 5.4 | 0.4% | Nov 20, 2023 | The Magic Embeds WordPress plugin before 3.1.2 does not validate and escape some of its shortcode attributes before outp... |
| CVE-2023-48309 | MEDIUM | 5.3 | 0.7% | Nov 20, 2023 | NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the defau... |
| CVE-2023-48300 | MEDIUM | 5.4 | 0.5% | Nov 20, 2023 | The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored ... |
| CVE-2023-38883 | MEDIUM | 6.1 | 0.6% | Nov 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic all... |
| CVE-2023-38882 | MEDIUM | 6.1 | 0.6% | Nov 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic all... |
| CVE-2023-38881 | MEDIUM | 6.1 | 0.6% | Nov 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic all... |
| CVE-2023-48223 | MEDIUM | 5.9 | 0.7% | Nov 20, 2023 | fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does not proper... |
| CVE-2023-48218 | MEDIUM | 5.3 | 0.6% | Nov 20, 2023 | The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3.... |
| CVE-2023-36013 | MEDIUM | 6.5 | 1.4% | Nov 20, 2023 | PowerShell Information Disclosure Vulnerability |
| CVE-2023-6197 | MEDIUM | 5.4 | 0.2% | Nov 20, 2023 | The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2023-48039 | MEDIUM | 5.5 | 0.3% | Nov 20, 2023 | GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leak in gf_mpd_parse_string media_tools/mpd.c:75. |
| CVE-2023-47772 | MEDIUM | 5.4 | 0.4% | Nov 20, 2023 | Contributor+ Stored Cross-Site Scripting (XSS) vulnerability in Slider Revolution <= 6.6.14. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now