2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45003 | MEDIUM | 6.1 | 0.3% | Oct 17, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins Social Feed | Custom Feed for Social Media N... |
| CVE-2023-5522 | MEDIUM | 4.3 | 0.4% | Oct 17, 2023 | Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post w... |
| CVE-2023-5339 | MEDIUM | 5.5 | 0.1% | Oct 17, 2023 | Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in loggin... |
| CVE-2023-45005 | MEDIUM | 6.1 | 0.3% | Oct 17, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Castos Seriously Simple Stats plugin <= 1.5.1 versions. |
| CVE-2023-44990 | MEDIUM | 4.8 | 0.3% | Oct 17, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Mana... |
| CVE-2023-44311 | MEDIUM | 6.1 | 0.5% | Oct 17, 2023 | Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplica... |
| CVE-2023-44310 | MEDIUM | 5.4 | 0.5% | Oct 17, 2023 | Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP... |
| CVE-2023-44309 | MEDIUM | 5.4 | 0.5% | Oct 17, 2023 | Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.... |
| CVE-2023-42629 | MEDIUM | 5.4 | 2.2% | Oct 17, 2023 | Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, ... |
| CVE-2023-24385 | MEDIUM | 4.8 | 0.3% | Oct 17, 2023 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in David Lingren Media Library Assistant plugin <= 3.11 ... |
| CVE-2023-42497 | MEDIUM | 6.1 | 0.5% | Oct 17, 2023 | Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through ... |
| CVE-2023-45358 | MEDIUM | 5.4 | 0.4% | Oct 17, 2023 | Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote... |
| CVE-2023-45357 | MEDIUM | 6.5 | 0.5% | Oct 17, 2023 | Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authen... |
| CVE-2023-34209 | MEDIUM | 4.3 | 0.4% | Oct 17, 2023 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in create template function in EasyUse MailHu... |
| CVE-2023-34208 | MEDIUM | 6.5 | 0.6% | Oct 17, 2023 | Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated us... |
| CVE-2023-38719 | MEDIUM | 4.4 | 0.2% | Oct 17, 2023 | IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation ... |
| CVE-2023-45807 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana following the license change in early 202... |
| CVE-2023-45540 | MEDIUM | 6.5 | 0.5% | Oct 16, 2023 | An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted s... |
| CVE-2023-44394 | MEDIUM | 4.3 | 0.6% | Oct 16, 2023 | MantisBT is an open source bug tracker. Due to insufficient access-level checks on the Wiki redirection page, any user c... |
| CVE-2023-44391 | MEDIUM | 5.3 | 0.4% | Oct 16, 2023 | Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even wh... |
| CVE-2023-43659 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Sc... |
| CVE-2023-43658 | MEDIUM | 6.1 | 0.5% | Oct 16, 2023 | dicourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar i... |
| CVE-2023-45542 | MEDIUM | 6.1 | 1.6% | Oct 16, 2023 | Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a cra... |
| CVE-2023-40851 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin p... |
| CVE-2023-5561 | MEDIUM | 5.3 | 3.9% | Oct 16, 2023 | WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attacke... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now