2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36409 | MEDIUM | 6.5 | 0.9% | Nov 7, 2023 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2023-36769 | MEDIUM | 5.4 | 0.4% | Nov 6, 2023 | Microsoft OneNote Spoofing Vulnerability |
| CVE-2023-45556 | MEDIUM | 5.4 | 0.5% | Nov 6, 2023 | Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via th... |
| CVE-2023-5771 | MEDIUM | 6.1 | 0.3% | Nov 6, 2023 | Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can sen... |
| CVE-2023-5605 | MEDIUM | 4.8 | 0.4% | Nov 6, 2023 | The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2023-5530 | MEDIUM | 4.8 | 0.6% | Nov 6, 2023 | The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could a... |
| CVE-2023-5354 | MEDIUM | 6.1 | 0.4% | Nov 6, 2023 | The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2023-5352 | MEDIUM | 4.3 | 0.4% | Nov 6, 2023 | The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing us... |
| CVE-2023-5228 | MEDIUM | 4.8 | 0.6% | Nov 6, 2023 | The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could all... |
| CVE-2023-5181 | MEDIUM | 4.8 | 0.4% | Nov 6, 2023 | The WP Discord Invite WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow... |
| CVE-2023-4930 | MEDIUM | 6.5 | 0.4% | Nov 6, 2023 | The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores a... |
| CVE-2023-4858 | MEDIUM | 4.8 | 0.4% | Nov 6, 2023 | The Simple Table Manager WordPress plugin through 1.5.6 does not sanitise and escape some of its settings, which could a... |
| CVE-2023-4810 | MEDIUM | 4.8 | 0.4% | Nov 6, 2023 | The Responsive Pricing Table WordPress plugin before 5.1.8 does not sanitise and escape some of its settings, which coul... |
| CVE-2023-46732 | MEDIUM | 6.1 | 2.2% | Nov 6, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulner... |
| CVE-2023-46254 | MEDIUM | 4.3 | 0.4% | Nov 6, 2023 | capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used... |
| CVE-2023-4700 | MEDIUM | 6.5 | 0.4% | Nov 6, 2023 | An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 1... |
| CVE-2023-46251 | MEDIUM | 6.1 | 0.5% | Nov 6, 2023 | MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape... |
| CVE-2023-40661 | MEDIUM | 6.4 | 1.2% | Nov 6, 2023 | Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process u... |
| CVE-2023-40660 | MEDIUM | 6.6 | 0.9% | Nov 6, 2023 | A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process... |
| CVE-2023-5969 | MEDIUM | 5.3 | 0.5% | Nov 6, 2023 | Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially... |
| CVE-2023-5968 | MEDIUM | 4.9 | 0.5% | Nov 6, 2023 | Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being i... |
| CVE-2023-5967 | MEDIUM | 4.3 | 0.5% | Nov 6, 2023 | Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a Use... |
| CVE-2023-5678 | MEDIUM | 5.3 | 4.5% | Nov 6, 2023 | Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be... |
| CVE-2023-5950 | MEDIUM | 6.1 | 0.5% | Nov 6, 2023 | Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerabi... |
| CVE-2023-5963 | MEDIUM | 4.3 | 0.5% | Nov 6, 2023 | An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now