2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43786 | MEDIUM | 5.5 | 0.5% | Oct 10, 2023 | A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local ... |
| CVE-2023-43785 | MEDIUM | 5.5 | 0.6% | Oct 10, 2023 | A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows ... |
| CVE-2023-43485 | MEDIUM | 5.5 | 0.2% | Oct 10, 2023 | When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audi... |
| CVE-2023-41964 | MEDIUM | 6.5 | 0.2% | Oct 10, 2023 | The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Sof... |
| CVE-2023-41253 | MEDIUM | 5.5 | 0.2% | Oct 10, 2023 | When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintex... |
| CVE-2023-39447 | MEDIUM | 4.4 | 0.2% | Oct 10, 2023 | When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.... |
| CVE-2023-44763 | MEDIUM | 5.4 | 0.6% | Oct 10, 2023 | Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cros... |
| CVE-2023-44315 | MEDIUM | 5.4 | 0.3% | Oct 10, 2023 | A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application improperly sanitizes ce... |
| CVE-2023-43623 | MEDIUM | 5.3 | 0.5% | Oct 10, 2023 | A vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All versions < V5.4.0), Mendix For... |
| CVE-2023-38640 | MEDIUM | 4.4 | 0.1% | Oct 10, 2023 | A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.22). The affected application is instal... |
| CVE-2023-37195 | MEDIUM | 4.4 | 0.2% | Oct 10, 2023 | A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (... |
| CVE-2023-37194 | MEDIUM | 6.7 | 0.2% | Oct 10, 2023 | A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (... |
| CVE-2023-5498 | MEDIUM | 4.3 | 0.2% | Oct 10, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository chiefonboarding/chiefonboarding prior to v2.0.47. |
| CVE-2023-5468 | MEDIUM | 5.4 | 0.3% | Oct 10, 2023 | The Slick Contact Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcscf-link' shortcode in ... |
| CVE-2023-5467 | MEDIUM | 5.4 | 0.4% | Oct 10, 2023 | The GEO my WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to,... |
| CVE-2023-44826 | MEDIUM | 5.4 | 0.4% | Oct 10, 2023 | Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a cra... |
| CVE-2023-42477 | MEDIUM | 6.5 | 0.4% | Oct 10, 2023 | SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a v... |
| CVE-2023-42475 | MEDIUM | 4.3 | 0.4% | Oct 10, 2023 | The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker... |
| CVE-2023-42474 | MEDIUM | 5.4 | 0.3% | Oct 10, 2023 | SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The... |
| CVE-2023-42473 | MEDIUM | 5.4 | 0.3% | Oct 10, 2023 | S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticat... |
| CVE-2023-41365 | MEDIUM | 4.3 | 0.3% | Oct 10, 2023 | SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault me... |
| CVE-2023-44813 | MEDIUM | 6.1 | 1.8% | Oct 9, 2023 | Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a c... |
| CVE-2023-44812 | MEDIUM | 6.1 | 1.9% | Oct 9, 2023 | Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a c... |
| CVE-2023-5461 | MEDIUM | 5.9 | 0.4% | Oct 9, 2023 | A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unkno... |
| CVE-2023-44821 | MEDIUM | 5.5 | 0.3% | Oct 9, 2023 | Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denia... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now