2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45281 | MEDIUM | 6.1 | 0.4% | Oct 19, 2023 | An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file. |
| CVE-2023-46033 | MEDIUM | 6.8 | 0.3% | Oct 19, 2023 | D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The... |
| CVE-2023-5654 | MEDIUM | 6.5 | 0.5% | Oct 19, 2023 | The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in ... |
| CVE-2023-35185 | MEDIUM | 6.8 | 1.1% | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM pri... |
| CVE-2023-31046 | MEDIUM | 6.5 | 1.5% | Oct 19, 2023 | A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditi... |
| CVE-2023-25753 | MEDIUM | 6.5 | 0.8% | Oct 19, 2023 | There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vu... |
| CVE-2023-34050 | MEDIUM | 4.3 | 1.5% | Oct 19, 2023 | In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class na... |
| CVE-2023-5254 | MEDIUM | 5.3 | 0.8% | Oct 19, 2023 | The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9... |
| CVE-2023-5639 | MEDIUM | 5.4 | 0.4% | Oct 19, 2023 | The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tmfshortcode' shor... |
| CVE-2023-5638 | MEDIUM | 5.4 | 0.5% | Oct 19, 2023 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcj_image' shortcode ... |
| CVE-2023-5336 | MEDIUM | 6.5 | 0.6% | Oct 19, 2023 | The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's ... |
| CVE-2023-4645 | MEDIUM | 5.3 | 0.6% | Oct 19, 2023 | The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 v... |
| CVE-2023-37504 | MEDIUM | 6.5 | 0.3% | Oct 19, 2023 | HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions ... |
| CVE-2023-36857 | MEDIUM | 6.5 | 0.3% | Oct 19, 2023 | Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a replay vulnerability which could allo... |
| CVE-2023-45909 | MEDIUM | 6.1 | 0.3% | Oct 18, 2023 | zzzcms v2.2.0 was discovered to contain an open redirect vulnerability. |
| CVE-2023-45958 | MEDIUM | 6.1 | 0.3% | Oct 18, 2023 | Thirty Bees Core v1.4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the backup_pa... |
| CVE-2023-45814 | MEDIUM | 5.3 | 0.4% | Oct 18, 2023 | Bunkum is an open-source protocol-agnostic request server for custom game servers. First, a little bit of background. So... |
| CVE-2023-20261 | MEDIUM | 6.5 | 0.5% | Oct 18, 2023 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve... |
| CVE-2023-5631 | MEDIUM | 5.4 | 70.9% | Oct 18, 2023 | Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a ... |
| CVE-2023-45632 | MEDIUM | 6.1 | 0.3% | Oct 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado SpiderVPlayer plugin <= 1.5.22 versions. |
| CVE-2023-45630 | MEDIUM | 6.1 | 0.3% | Oct 18, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails pl... |
| CVE-2023-45628 | MEDIUM | 5.4 | 0.3% | Oct 18, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in QROkes QR Twitter Widget plugin <= 0.2.3 version... |
| CVE-2023-45607 | MEDIUM | 5.4 | 0.3% | Oct 18, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Hector Cabrera WordPress Popular Posts plugin <=... |
| CVE-2023-45604 | MEDIUM | 4.8 | 0.3% | Oct 18, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Reilly Get Custom Field Values plugin <= 4.0.1 v... |
| CVE-2023-45602 | MEDIUM | 6.1 | 0.3% | Oct 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.785 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now