2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39159 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Fraud Prevention For Woocommerce plugin <= 2.1.5 versions... |
| CVE-2023-32792 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker... |
| CVE-2023-32791 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker... |
| CVE-2023-32790 | MEDIUM | 6.1 | 0.3% | Oct 3, 2023 | Cross-Site Scripting (XSS) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to inj... |
| CVE-2023-32671 | MEDIUM | 5.4 | 0.3% | Oct 3, 2023 | A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an at... |
| CVE-2023-32670 | MEDIUM | 5.4 | 0.4% | Oct 3, 2023 | Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privile... |
| CVE-2023-32669 | MEDIUM | 5.4 | 0.3% | Oct 3, 2023 | Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated us... |
| CVE-2023-5351 | MEDIUM | 5.4 | 0.5% | Oct 3, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1. |
| CVE-2023-4101 | MEDIUM | 6.5 | 0.4% | Oct 3, 2023 | The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has suffi... |
| CVE-2023-4099 | MEDIUM | 6.5 | 0.3% | Oct 3, 2023 | The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource... |
| CVE-2023-0828 | MEDIUM | 6.1 | 0.3% | Oct 3, 2023 | Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie val... |
| CVE-2023-28571 | MEDIUM | 5.5 | 0.1% | Oct 3, 2023 | Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan. |
| CVE-2023-5334 | MEDIUM | 5.4 | 0.3% | Oct 3, 2023 | The WP Responsive header image slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sp_responsi... |
| CVE-2023-3335 | MEDIUM | 5.5 | 0.2% | Oct 3, 2023 | Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local... |
| CVE-2023-43627 | MEDIUM | 5.7 | 0.3% | Oct 3, 2023 | Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier... |
| CVE-2023-39429 | MEDIUM | 5.4 | 0.3% | Oct 3, 2023 | Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to i... |
| CVE-2023-32572 | MEDIUM | 4.9 | 0.4% | Oct 3, 2023 | A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention l... |
| CVE-2023-31042 | MEDIUM | 4.3 | 0.5% | Oct 2, 2023 | A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBlade’s object store protocol can i... |
| CVE-2023-44012 | MEDIUM | 6.1 | 1.3% | Oct 2, 2023 | Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the he... |
| CVE-2023-43836 | MEDIUM | 6.5 | 0.6% | Oct 2, 2023 | There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information |
| CVE-2023-43297 | MEDIUM | 5.4 | 0.2% | Oct 2, 2023 | An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access toke... |
| CVE-2023-43267 | MEDIUM | 5.4 | 0.3% | Oct 2, 2023 | A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to exec... |
| CVE-2023-44463 | MEDIUM | 5.3 | 0.5% | Oct 2, 2023 | An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to tr... |
| CVE-2023-37605 | MEDIUM | 5.5 | 0.2% | Oct 2, 2023 | Weak Exception Handling vulnerability in baramundi software GmbH EMM Agent 23.1.50 and before allows an attacker to caus... |
| CVE-2023-0809 | MEDIUM | 5.3 | 0.6% | Oct 2, 2023 | In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packet... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now