2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3746 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allo... |
| CVE-2023-3707 | MEDIUM | 4.3 | 0.5% | Oct 16, 2023 | The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong t... |
| CVE-2023-3706 | MEDIUM | 4.3 | 0.5% | Oct 16, 2023 | The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to ... |
| CVE-2023-3279 | MEDIUM | 4.9 | 0.8% | Oct 16, 2023 | The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to g... |
| CVE-2023-29484 | MEDIUM | 6.5 | 0.3% | Oct 16, 2023 | In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password. |
| CVE-2023-45683 | MEDIUM | 6.1 | 0.4% | Oct 16, 2023 | github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the AC... |
| CVE-2023-45669 | MEDIUM | 5.3 | 0.5% | Oct 16, 2023 | WebAuthn4J Spring Security provides Web Authentication specification support for Spring applications. Affected versions ... |
| CVE-2023-45660 | MEDIUM | 4.3 | 0.6% | Oct 16, 2023 | Nextcloud mail is an email app for the Nextcloud home server platform. In affected versions a missing check of origin, t... |
| CVE-2023-45148 | MEDIUM | 4.3 | 0.7% | Oct 16, 2023 | Nextcloud is an open source home cloud server. When Memcached is used as `memcache.distributed` the rate limiting in Nex... |
| CVE-2023-45690 | MEDIUM | 4.9 | 1.5% | Oct 16, 2023 | Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user that's aut... |
| CVE-2023-45689 | MEDIUM | 6.5 | 0.8% | Oct 16, 2023 | Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux al... |
| CVE-2023-45688 | MEDIUM | 4.3 | 0.6% | Oct 16, 2023 | Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an auth... |
| CVE-2023-5575 | MEDIUM | 6.5 | 0.6% | Oct 16, 2023 | Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker... |
| CVE-2023-46066 | MEDIUM | 5.4 | 0.3% | Oct 16, 2023 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Codedrafty Mediabay – Media Library Folders plugin <=... |
| CVE-2023-44987 | MEDIUM | 4.8 | 0.3% | Oct 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Timely - Appointment software Timely Booking Button pl... |
| CVE-2023-44986 | MEDIUM | 4.8 | 0.3% | Oct 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Abandoned Cart Lite for WooCommerce pl... |
| CVE-2023-44985 | MEDIUM | 5.4 | 0.3% | Oct 16, 2023 | Auth. (contributo+) Stored Cross-Site Scripting (XSS) vulnerability in Cytech BuddyMeet plugin <= 2.2.0 versions. |
| CVE-2023-44984 | MEDIUM | 5.4 | 0.3% | Oct 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Robin Wilson bbp style pack plugin <= 5.6.7 vers... |
| CVE-2023-44229 | MEDIUM | 4.8 | 0.3% | Oct 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Tiny Carousel Horizontal Slider plugin <... |
| CVE-2023-5595 | MEDIUM | 5.5 | 0.3% | Oct 16, 2023 | Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV. |
| CVE-2023-5421 | MEDIUM | 5.5 | 0.4% | Oct 16, 2023 | An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate th... |
| CVE-2023-4834 | MEDIUM | 4.3 | 0.3% | Oct 16, 2023 | In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an ... |
| CVE-2023-4620 | MEDIUM | 6.1 | 0.5% | Oct 16, 2023 | The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowin... |
| CVE-2023-45757 | MEDIUM | 6.1 | 1.0% | Oct 16, 2023 | Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz p... |
| CVE-2023-43666 | MEDIUM | 6.5 | 0.4% | Oct 16, 2023 | Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now