2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46755 | MEDIUM | 5.3 | 0.4% | Nov 8, 2023 | Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerabilit... |
| CVE-2023-46483 | MEDIUM | 5.4 | 0.4% | Nov 8, 2023 | Cross Site Scripting vulnerability in timetec AWDMS v.2.0 allows an attacker to obtain sensitive information via a craft... |
| CVE-2023-41270 | MEDIUM | 4.3 | 0.4% | Nov 8, 2023 | Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Smart TV UE40D7000 version T-GAPDEUC-... |
| CVE-2023-4061 | MEDIUM | 6.5 | 0.8% | Nov 8, 2023 | A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possib... |
| CVE-2023-6002 | MEDIUM | 6.1 | 0.4% | Nov 8, 2023 | YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files ca... |
| CVE-2023-46001 | MEDIUM | 5.5 | 0.3% | Nov 7, 2023 | Buffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denia... |
| CVE-2023-5982 | MEDIUM | 5.4 | 0.2% | Nov 7, 2023 | The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in... |
| CVE-2023-5819 | MEDIUM | 4.8 | 0.5% | Nov 7, 2023 | The Amazonify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to... |
| CVE-2023-5818 | MEDIUM | 4.3 | 0.2% | Nov 7, 2023 | The Amazonify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8... |
| CVE-2023-4956 | MEDIUM | 4.3 | 0.5% | Nov 7, 2023 | A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user in... |
| CVE-2023-4154 | MEDIUM | 6.5 | 1.2% | Nov 7, 2023 | A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directo... |
| CVE-2023-46252 | MEDIUM | 6.1 | 0.5% | Nov 7, 2023 | Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in ... |
| CVE-2023-46744 | MEDIUM | 5.4 | 0.5% | Nov 7, 2023 | Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (X... |
| CVE-2023-46737 | MEDIUM | 5.3 | 0.6% | Nov 7, 2023 | Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker contro... |
| CVE-2023-32966 | MEDIUM | 6.1 | 0.2% | Nov 7, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab Jazz Popups leads to Stored XSS.This issue affects Jazz Popup... |
| CVE-2023-28499 | MEDIUM | 5.4 | 0.5% | Nov 7, 2023 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML... |
| CVE-2023-4272 | MEDIUM | 5.5 | 0.3% | Nov 7, 2023 | A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory. ... |
| CVE-2023-41425 | MEDIUM | 6.1 | 54.3% | Nov 7, 2023 | Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code... |
| CVE-2023-5709 | MEDIUM | 6.5 | 0.9% | Nov 7, 2023 | The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a... |
| CVE-2023-5703 | MEDIUM | 5.4 | 0.6% | Nov 7, 2023 | The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2023-5669 | MEDIUM | 5.4 | 0.6% | Nov 7, 2023 | The Featured Image Caption plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode ... |
| CVE-2023-5661 | MEDIUM | 5.4 | 0.5% | Nov 7, 2023 | The Social Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialfeed' shortcod... |
| CVE-2023-5660 | MEDIUM | 5.4 | 0.7% | Nov 7, 2023 | The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s... |
| CVE-2023-5659 | MEDIUM | 5.4 | 0.5% | Nov 7, 2023 | The Interact: Embed A Quiz On Your Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2023-5577 | MEDIUM | 5.4 | 0.5% | Nov 7, 2023 | The Bitly's plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpbitly' shortcode in al... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now