2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30734 | MEDIUM | 5.5 | 0.2% | Oct 4, 2023 | Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive... |
| CVE-2023-30731 | MEDIUM | 4.6 | 0.2% | Oct 4, 2023 | Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to ins... |
| CVE-2023-5357 | MEDIUM | 5.4 | 0.4% | Oct 4, 2023 | The Instagram for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions... |
| CVE-2023-5291 | MEDIUM | 5.4 | 0.4% | Oct 4, 2023 | The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in vers... |
| CVE-2023-3213 | MEDIUM | 5.3 | 0.4% | Oct 4, 2023 | The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2023-35905 | MEDIUM | 5.4 | 0.3% | Oct 4, 2023 | IBM FileNet Content Manager 5.5.8, 5.5.10, and 5.5.11 is vulnerable to cross-site scripting. This vulnerability allows u... |
| CVE-2023-43953 | MEDIUM | 5.4 | 0.3% | Oct 3, 2023 | SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component. |
| CVE-2023-43952 | MEDIUM | 5.4 | 0.3% | Oct 3, 2023 | SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management comp... |
| CVE-2023-43951 | MEDIUM | 5.4 | 0.3% | Oct 3, 2023 | SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component. |
| CVE-2023-43898 | MEDIUM | 5.5 | 0.3% | Oct 3, 2023 | Nothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulne... |
| CVE-2023-40519 | MEDIUM | 6.1 | 0.4% | Oct 3, 2023 | A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized... |
| CVE-2023-4732 | MEDIUM | 4.7 | 0.2% | Oct 3, 2023 | A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker... |
| CVE-2023-34970 | MEDIUM | 4.7 | 0.3% | Oct 3, 2023 | A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bou... |
| CVE-2023-33200 | MEDIUM | 4.7 | 0.3% | Oct 3, 2023 | A local non-privileged user can make improper GPU processing operations to exploit a software race condition. If the sys... |
| CVE-2023-4564 | MEDIUM | 4.8 | 0.4% | Oct 3, 2023 | This vulnerability could allow an attacker to store a malicious JavaScript payload in the broadcast message parameter wi... |
| CVE-2023-3196 | MEDIUM | 4.8 | 0.4% | Oct 3, 2023 | This vulnerability could allow an attacker to store a malicious JavaScript payload in the login footer and login page de... |
| CVE-2023-4886 | MEDIUM | 4.4 | 0.3% | Oct 3, 2023 | A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain... |
| CVE-2023-4885 | MEDIUM | 5.9 | 0.3% | Oct 3, 2023 | Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network Function) communication... |
| CVE-2023-39158 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Banner Management For WooCommerce plugin <= 2.4.2 version... |
| CVE-2023-2544 | MEDIUM | 6.5 | 0.4% | Oct 3, 2023 | Authorization bypass vulnerability in UPV PEIX, affecting the component "pdf_curri_new.php". Through a POST request, an ... |
| CVE-2023-5353 | MEDIUM | 6.5 | 0.6% | Oct 3, 2023 | Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1. |
| CVE-2023-42508 | MEDIUM | 6.5 | 0.4% | Oct 3, 2023 | JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, whi... |
| CVE-2023-40212 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versio... |
| CVE-2023-40198 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Antsanchez Easy Cookie Law plugin <= 3.1 versions. |
| CVE-2023-40009 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Pipes plugin <= 1.4.0 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now