2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40121 | MEDIUM | 5.5 | 0.2% | Oct 27, 2023 | In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This c... |
| CVE-2023-32738 | MEDIUM | 4.8 | 0.3% | Oct 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alkaweb Eonet Manual User Approve plugin <= 2.1.3 vers... |
| CVE-2023-46407 | MEDIUM | 5.5 | 0.3% | Oct 27, 2023 | FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the... |
| CVE-2023-29009 | MEDIUM | 6.1 | 0.5% | Oct 27, 2023 | baserCMS is a website development framework with WebAPI that runs on PHP8 and CakePHP4. There is a XSS Vulnerability in ... |
| CVE-2023-46246 | MEDIUM | 5.5 | 0.4% | Oct 27, 2023 | Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_g... |
| CVE-2023-46394 | MEDIUM | 5.4 | 0.3% | Oct 27, 2023 | A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to exe... |
| CVE-2023-5821 | MEDIUM | 6.5 | 0.3% | Oct 27, 2023 | The Thumbnail carousel slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is d... |
| CVE-2023-5705 | MEDIUM | 5.4 | 0.4% | Oct 27, 2023 | The VK Filter Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk_filter_searc... |
| CVE-2023-5817 | MEDIUM | 5.4 | 0.5% | Oct 27, 2023 | The Neon text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's neontext_box shortcode ... |
| CVE-2023-5774 | MEDIUM | 5.4 | 0.5% | Oct 27, 2023 | The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in... |
| CVE-2023-46199 | MEDIUM | 4.8 | 0.3% | Oct 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Triberr plugin <= 4.1.1 versions. |
| CVE-2023-46194 | MEDIUM | 6.1 | 0.3% | Oct 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <... |
| CVE-2023-46192 | MEDIUM | 4.8 | 0.3% | Oct 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Internet Marketing Ninjas Internal Link Building plugi... |
| CVE-2023-46153 | MEDIUM | 6.1 | 0.4% | Oct 27, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.9 versions. |
| CVE-2023-46093 | MEDIUM | 4.8 | 0.3% | Oct 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in LionScripts.Com Webmaster Tools plugin <= 2.0 versions... |
| CVE-2023-46091 | MEDIUM | 4.8 | 0.3% | Oct 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bala Krishna, Sergey Yakovlev Category SEO Meta Tags p... |
| CVE-2023-5051 | MEDIUM | 5.4 | 0.4% | Oct 27, 2023 | The CallRail Phone Call Tracking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callrail_for... |
| CVE-2023-46504 | MEDIUM | 5.4 | 0.4% | Oct 27, 2023 | Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a physically proximate attacker to execute a... |
| CVE-2023-46503 | MEDIUM | 6.1 | 0.5% | Oct 27, 2023 | Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a remote attacker to execute arbitrary code ... |
| CVE-2023-5811 | MEDIUM | 4.8 | 0.5% | Oct 27, 2023 | A vulnerability, which was classified as problematic, was found in flusity CMS. Affected is the function loadPostAddForm... |
| CVE-2023-5810 | MEDIUM | 4.8 | 0.5% | Oct 27, 2023 | A vulnerability, which was classified as problematic, has been found in flusity CMS. This issue affects the function loa... |
| CVE-2023-46505 | MEDIUM | 6.1 | 0.4% | Oct 27, 2023 | Cross Site Scripting vulnerability in FanCMS v.1.0.0 allows an attacker to execute arbitrary code via the content1 param... |
| CVE-2023-46491 | MEDIUM | 6.1 | 0.4% | Oct 27, 2023 | ZenTao Biz version 4.1.3 and before has a Cross Site Scripting (XSS) vulnerability in the Version Library. |
| CVE-2023-46374 | MEDIUM | 6.1 | 0.4% | Oct 27, 2023 | ZenTao Enterprise Edition version 4.1.3 and before is vulnerable to Cross Site Scripting (XSS). |
| CVE-2023-42188 | MEDIUM | 6.5 | 0.2% | Oct 27, 2023 | IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (CSRF). |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now