2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5164 | MEDIUM | 5.4 | 0.4% | Oct 30, 2023 | The Bellows Accordion Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions ... |
| CVE-2023-5049 | MEDIUM | 5.4 | 0.5% | Oct 30, 2023 | The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'raf... |
| CVE-2023-42431 | MEDIUM | 5.4 | 0.3% | Oct 30, 2023 | Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbi... |
| CVE-2023-45746 | MEDIUM | 5.4 | 0.4% | Oct 30, 2023 | Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary ... |
| CVE-2023-46867 | MEDIUM | 6.5 | 0.5% | Oct 30, 2023 | In International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a... |
| CVE-2023-46866 | MEDIUM | 6.5 | 0.6% | Oct 30, 2023 | In International Color Consortium DemoIccMAX 79ecb74, CIccCLUT::Interp3d in IccProfLib/IccTagLut.cpp in libSampleICC.a a... |
| CVE-2023-5842 | MEDIUM | 4.8 | 0.5% | Oct 30, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5. |
| CVE-2023-4393 | MEDIUM | 6.1 | 0.3% | Oct 30, 2023 | HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform... |
| CVE-2023-46864 | MEDIUM | 5.3 | 0.7% | Oct 30, 2023 | Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/d... |
| CVE-2023-46862 | MEDIUM | 4.7 | 0.2% | Oct 29, 2023 | An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit, an io_uring/fdinfo.c io_ur... |
| CVE-2023-46858 | MEDIUM | 5.4 | 0.6% | Oct 29, 2023 | Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodl... |
| CVE-2023-43041 | MEDIUM | 4.9 | 0.5% | Oct 29, 2023 | IBM QRadar SIEM 7.5 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain ... |
| CVE-2023-5837 | MEDIUM | 6.1 | 0.4% | Oct 28, 2023 | A vulnerability classified as problematic was found in AlexanderLivanov FotosCMS2 up to 2.4.3. This vulnerability affect... |
| CVE-2023-46854 | MEDIUM | 6.1 | 0.4% | Oct 28, 2023 | Proxmox proxmox-widget-toolkit before 4.0.9, as used in multiple Proxmox products, allows XSS via the edit notes feature... |
| CVE-2023-45897 | MEDIUM | 5.5 | 0.4% | Oct 28, 2023 | exfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set. |
| CVE-2023-5835 | MEDIUM | 6.1 | 0.4% | Oct 28, 2023 | A vulnerability classified as problematic was found in hu60t hu60wap6. Affected by this vulnerability is the function ma... |
| CVE-2023-46467 | MEDIUM | 5.4 | 0.5% | Oct 28, 2023 | Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via... |
| CVE-2023-46490 | MEDIUM | 6.5 | 1.4% | Oct 27, 2023 | SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actio... |
| CVE-2023-46211 | MEDIUM | 5.4 | 0.3% | Oct 27, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Pa... |
| CVE-2023-46209 | MEDIUM | 6.1 | 0.3% | Oct 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in G5Theme Grid Plus – Unlimited grid plugin <= 1.3.2 version... |
| CVE-2023-46208 | MEDIUM | 6.1 | 0.3% | Oct 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing ... |
| CVE-2023-46200 | MEDIUM | 4.8 | 0.3% | Oct 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Stephen Darlington, Wandle Software Limited Smart App ... |
| CVE-2023-40139 | MEDIUM | 5.5 | 0.1% | Oct 27, 2023 | In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lea... |
| CVE-2023-40133 | MEDIUM | 5.5 | 0.2% | Oct 27, 2023 | In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused depu... |
| CVE-2023-40123 | MEDIUM | 5.5 | 0.1% | Oct 27, 2023 | In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now