2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46802 | MEDIUM | 5.5 | 0.2% | Nov 6, 2023 | e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configurat... |
| CVE-2023-47272 | MEDIUM | 6.1 | 0.6% | Nov 6, 2023 | Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used fo... |
| CVE-2023-47271 | MEDIUM | 5.3 | 0.6% | Nov 6, 2023 | PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other pr... |
| CVE-2023-47260 | MEDIUM | 6.1 | 0.4% | Nov 5, 2023 | Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails. |
| CVE-2023-47259 | MEDIUM | 6.1 | 0.4% | Nov 5, 2023 | Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter. |
| CVE-2023-47258 | MEDIUM | 6.1 | 0.4% | Nov 5, 2023 | Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter. |
| CVE-2023-47249 | MEDIUM | 6.5 | 0.5% | Nov 5, 2023 | In International Color Consortium DemoIccMAX 79ecb74, a CIccXmlArrayType:::ParseText function (for unsigned short) in Ic... |
| CVE-2023-46964 | MEDIUM | 6.1 | 0.5% | Nov 5, 2023 | Cross Site Scripting (XSS) vulnerability in Hillstone Next Generation FireWall SG-6000-e3960 v.5.5 allows a remote attac... |
| CVE-2023-46963 | MEDIUM | 5.3 | 0.5% | Nov 4, 2023 | An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attack... |
| CVE-2023-45189 | MEDIUM | 6.5 | 0.5% | Nov 3, 2023 | A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7... |
| CVE-2023-47233 | MEDIUM | 4.3 | 0.3% | Nov 3, 2023 | The brcm80211 component in the Linux kernel through 6.5.10 has a brcmf_cfg80211_detach use-after-free in the device unpl... |
| CVE-2023-39301 | MEDIUM | 4.3 | 0.3% | Nov 3, 2023 | A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. I... |
| CVE-2023-5946 | MEDIUM | 6.1 | 0.4% | Nov 3, 2023 | The Digirisk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_group_id' parameter i... |
| CVE-2023-5945 | MEDIUM | 5.4 | 0.3% | Nov 3, 2023 | The video carousel slider with lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0.... |
| CVE-2023-5707 | MEDIUM | 5.4 | 0.5% | Nov 3, 2023 | The SEO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slider' shortcode and... |
| CVE-2023-4592 | MEDIUM | 6.1 | 0.4% | Nov 3, 2023 | A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability... |
| CVE-2023-4768 | MEDIUM | 6.1 | 2.9% | Nov 3, 2023 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerabilit... |
| CVE-2023-4767 | MEDIUM | 6.1 | 2.9% | Nov 3, 2023 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerabilit... |
| CVE-2023-4091 | MEDIUM | 6.5 | 1.2% | Nov 3, 2023 | A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permis... |
| CVE-2023-46846 | MEDIUM | 5.3 | 5.3% | Nov 3, 2023 | SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform R... |
| CVE-2023-42670 | MEDIUM | 6.5 | 1.1% | Nov 3, 2023 | A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiat... |
| CVE-2023-5948 | MEDIUM | 5.5 | 0.3% | Nov 3, 2023 | Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91. |
| CVE-2023-41356 | MEDIUM | 6.5 | 0.9% | Nov 3, 2023 | NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthentic... |
| CVE-2023-41354 | MEDIUM | 5.3 | 0.4% | Nov 3, 2023 | Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated ... |
| CVE-2023-45362 | MEDIUM | 4.3 | 0.6% | Nov 3, 2023 | An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now