2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26147 | MEDIUM | 6.1 | 0.4% | Sep 29, 2023 | All versions of the package ithewei/libhv are vulnerable to HTTP Response Splitting when untrusted user input is used to... |
| CVE-2023-26146 | MEDIUM | 6.1 | 0.4% | Sep 29, 2023 | All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name... |
| CVE-2023-3775 | MEDIUM | 4.9 | 0.5% | Sep 29, 2023 | A Vault Enterprise Sentinel Role Governing Policy created by an operator to restrict access to resources in one namespac... |
| CVE-2023-44174 | MEDIUM | 5.4 | 0.4% | Sep 28, 2023 | Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Stored Cross-Site Scripting vulnerability. ... |
| CVE-2023-44173 | MEDIUM | 5.4 | 0.3% | Sep 28, 2023 | Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability.... |
| CVE-2023-41911 | MEDIUM | 5.5 | 0.1% | Sep 28, 2023 | Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2). |
| CVE-2023-43323 | MEDIUM | 6.5 | 1.9% | Sep 28, 2023 | mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP a... |
| CVE-2023-43664 | MEDIUM | 4.3 | 0.4% | Sep 28, 2023 | PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list a... |
| CVE-2023-43663 | MEDIUM | 4.3 | 0.3% | Sep 28, 2023 | PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled ... |
| CVE-2023-43657 | MEDIUM | 6.1 | 0.5% | Sep 28, 2023 | discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encry... |
| CVE-2023-43884 | MEDIUM | 5.4 | 0.4% | Sep 28, 2023 | A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attacke... |
| CVE-2023-43879 | MEDIUM | 4.8 | 0.5% | Sep 28, 2023 | Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafte... |
| CVE-2023-43878 | MEDIUM | 5.4 | 0.5% | Sep 28, 2023 | Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via ... |
| CVE-2023-43876 | MEDIUM | 5.4 | 0.4% | Sep 28, 2023 | A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary w... |
| CVE-2023-5215 | MEDIUM | 6.5 | 0.7% | Sep 28, 2023 | A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-... |
| CVE-2023-43874 | MEDIUM | 5.4 | 0.6% | Sep 28, 2023 | Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code ... |
| CVE-2023-43873 | MEDIUM | 5.4 | 0.5% | Sep 28, 2023 | A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a c... |
| CVE-2023-43872 | MEDIUM | 5.4 | 0.5% | Sep 28, 2023 | A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Sit... |
| CVE-2023-43871 | MEDIUM | 5.4 | 0.4% | Sep 28, 2023 | A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scriptin... |
| CVE-2023-42756 | MEDIUM | 4.7 | 0.3% | Sep 28, 2023 | A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SW... |
| CVE-2023-5233 | MEDIUM | 5.4 | 0.4% | Sep 28, 2023 | The Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fawesome' shortcode ... |
| CVE-2023-5232 | MEDIUM | 5.4 | 0.4% | Sep 28, 2023 | The Font Awesome More Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' shortcode in ve... |
| CVE-2023-5230 | MEDIUM | 5.4 | 0.3% | Sep 28, 2023 | The TM WooCommerce Compare & Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tm_woo_wish... |
| CVE-2023-44276 | MEDIUM | 5.4 | 0.5% | Sep 28, 2023 | OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard. |
| CVE-2023-44275 | MEDIUM | 5.4 | 0.5% | Sep 28, 2023 | OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now