2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47309 | MEDIUM | 5.4 | 0.4% | Nov 15, 2023 | Nukium nkmgls before version 3.0.2 is vulnerable to Cross Site Scripting (XSS) via NkmGlsCheckoutModuleFrontController::... |
| CVE-2023-43588 | MEDIUM | 6.5 | 0.7% | Nov 15, 2023 | Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disc... |
| CVE-2023-38544 | MEDIUM | 5.5 | 0.4% | Nov 15, 2023 | A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. ... |
| CVE-2023-5189 | MEDIUM | 6.5 | 0.8% | Nov 14, 2023 | A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball s... |
| CVE-2023-47518 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Matthew Muro Restrict Categories plugin <= 2.6.4 versions. |
| CVE-2023-47517 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.23.11.6 versions. |
| CVE-2023-45627 | MEDIUM | 6.5 | 0.8% | Nov 14, 2023 | An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulner... |
| CVE-2023-41570 | MEDIUM | 5.3 | 0.5% | Nov 14, 2023 | MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API. |
| CVE-2023-39205 | MEDIUM | 6.5 | 0.9% | Nov 14, 2023 | Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of serv... |
| CVE-2023-39202 | MEDIUM | 5.5 | 0.2% | Nov 14, 2023 | Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a deni... |
| CVE-2023-39199 | MEDIUM | 6.5 | 0.6% | Nov 14, 2023 | Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information di... |
| CVE-2023-47532 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themeum WP Crowdfunding plugin <= 2.1.6 versions. |
| CVE-2023-47528 | MEDIUM | 4.8 | 0.4% | Nov 14, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sajjad Hossain Sagor WP Edit Username plugin <= 1.0.5 ... |
| CVE-2023-47524 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability (requires PHP 8.x) in CodeBard CodeBard's Patron Button and W... |
| CVE-2023-47522 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Feed plugin <= 2.2.1 versions. |
| CVE-2023-47520 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Uno (miunosoft) Responsive Column Widgets plugin <... |
| CVE-2023-46581 | MEDIUM | 5.5 | 0.3% | Nov 14, 2023 | SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name... |
| CVE-2023-46580 | MEDIUM | 5.4 | 0.5% | Nov 14, 2023 | Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the... |
| CVE-2023-46026 | MEDIUM | 4.8 | 0.4% | Nov 14, 2023 | Cross Site Scripting (XSS) vulnerability in profile.php in phpgurukul Teacher Subject Allocation Management System 1.0 a... |
| CVE-2023-46025 | MEDIUM | 4.9 | 0.7% | Nov 14, 2023 | SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows at... |
| CVE-2023-46023 | MEDIUM | 6.5 | 0.6% | Nov 14, 2023 | SQL injection vulnerability in addTask.php in Code-Projects Simple Task List 1.0 allows attackers to obtain sensitive in... |
| CVE-2023-36558 | MEDIUM | 5.5 | 1.1% | Nov 14, 2023 | ASP.NET Core Security Feature Bypass Vulnerability |
| CVE-2023-47641 | MEDIUM | 6.5 | 0.8% | Nov 14, 2023 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a secu... |
| CVE-2023-47549 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3.... |
| CVE-2023-47547 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommer... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now