2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47097 | MEDIUM | 5.4 | 0.4% | Nov 1, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the Server Template under System Setting in Virtualmin 7.7 allows r... |
| CVE-2023-47096 | MEDIUM | 5.4 | 0.4% | Nov 1, 2023 | A Reflected Cross-Site Scripting (XSS) vulnerability in the Cloudmin Services Client under System Setting in Virtualmin ... |
| CVE-2023-47095 | MEDIUM | 5.4 | 0.4% | Nov 1, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the Custom fields of Edit Virtual Server under System Customization... |
| CVE-2023-47094 | MEDIUM | 5.4 | 0.4% | Nov 1, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the Account Plans tab of System Settings in Virtualmin 7.7 allows r... |
| CVE-2023-46278 | MEDIUM | 6.5 | 0.6% | Nov 1, 2023 | Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.1.0 to 4.1.1 allows a remote authenticated at... |
| CVE-2023-46378 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted stri... |
| CVE-2023-39695 | MEDIUM | 5.3 | 0.4% | Oct 31, 2023 | Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter... |
| CVE-2023-44484 | MEDIUM | 6.1 | 0.4% | Oct 31, 2023 | Online Blood Donation Management System v1.0 is vulnerable to a Stored Cross-Site Scripting vulnerability. The 'firstNam... |
| CVE-2023-39610 | MEDIUM | 6.5 | 0.3% | Oct 31, 2023 | An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Ser... |
| CVE-2023-20886 | MEDIUM | 6.1 | 0.4% | Oct 31, 2023 | VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a ... |
| CVE-2023-37831 | MEDIUM | 5.3 | 0.5% | Oct 31, 2023 | An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server re... |
| CVE-2023-43796 | MEDIUM | 5.3 | 0.9% | Oct 31, 2023 | Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote ... |
| CVE-2023-46722 | MEDIUM | 6.1 | 0.5% | Oct 31, 2023 | The Pimcore Admin Classic Bundle provides a backend UI for Pimcore. Prior to version 1.2.0, a cross-site scripting vulne... |
| CVE-2023-46255 | MEDIUM | 6.5 | 0.4% | Oct 31, 2023 | SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application per... |
| CVE-2023-46250 | MEDIUM | 5.5 | 0.2% | Oct 31, 2023 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions 3.7.0 ... |
| CVE-2023-46237 | MEDIUM | 5.3 | 0.5% | Oct 31, 2023 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint... |
| CVE-2023-46235 | MEDIUM | 6.1 | 0.3% | Oct 31, 2023 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10.15, due to a... |
| CVE-2023-5519 | MEDIUM | 4.3 | 0.2% | Oct 31, 2023 | The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attacke... |
| CVE-2023-5458 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | The CITS Support svg, webp Media and TTF,OTF File Upload WordPress plugin before 3.0 does not sanitise uploaded SVG file... |
| CVE-2023-5307 | MEDIUM | 6.1 | 0.5% | Oct 31, 2023 | The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, whic... |
| CVE-2023-5243 | MEDIUM | 4.8 | 0.4% | Oct 31, 2023 | The Login Screen Manager WordPress plugin through 3.5.2 does not sanitize and escape some of its settings, which could a... |
| CVE-2023-5238 | MEDIUM | 6.1 | 0.4% | Oct 31, 2023 | The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2023-5237 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes be... |
| CVE-2023-5229 | MEDIUM | 4.8 | 0.4% | Oct 31, 2023 | The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high priv... |
| CVE-2023-5211 | MEDIUM | 6.1 | 0.4% | Oct 31, 2023 | The Fattura24 WordPress plugin before 6.2.8 does not sanitize or escape the 'id' parameter before outputting it back in ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now