2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43645 | MEDIUM | 5.9 | 0.8% | Sep 27, 2023 | OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA is vulnerabl... |
| CVE-2023-43614 | MEDIUM | 6.1 | 0.6% | Sep 27, 2023 | Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote ... |
| CVE-2023-43493 | MEDIUM | 4.9 | 0.8% | Sep 27, 2023 | SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or ... |
| CVE-2023-43484 | MEDIUM | 6.1 | 0.6% | Sep 27, 2023 | Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauth... |
| CVE-2023-43331 | MEDIUM | 5.4 | 0.5% | Sep 27, 2023 | A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitr... |
| CVE-2023-43263 | MEDIUM | 6.1 | 0.7% | Sep 27, 2023 | A Cross-site scripting (XSS) vulnerability in Froala Editor v.4.1.1 allows attackers to execute arbitrary code via the M... |
| CVE-2023-43232 | MEDIUM | 5.4 | 0.4% | Sep 27, 2023 | A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows at... |
| CVE-2023-42453 | MEDIUM | 4.3 | 0.7% | Sep 27, 2023 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forg... |
| CVE-2023-41996 | MEDIUM | 5.5 | 0.3% | Sep 27, 2023 | The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6. Apps that fail verification che... |
| CVE-2023-41986 | MEDIUM | 5.5 | 0.3% | Sep 27, 2023 | The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may b... |
| CVE-2023-41981 | MEDIUM | 4.4 | 0.4% | Sep 27, 2023 | The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and ... |
| CVE-2023-41980 | MEDIUM | 5.5 | 0.3% | Sep 27, 2023 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonom... |
| CVE-2023-41979 | MEDIUM | 4.7 | 0.2% | Sep 27, 2023 | A race condition was addressed with improved locking. This issue is fixed in macOS Sonoma 14. An app may be able to modi... |
| CVE-2023-41968 | MEDIUM | 5.5 | 0.4% | Sep 27, 2023 | This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS... |
| CVE-2023-41962 | MEDIUM | 6.1 | 0.6% | Sep 27, 2023 | Cross-site scripting vulnerability in Credit Card Payment Setup page of Welcart e-Commerce versions 2.7 to 2.8.21 allows... |
| CVE-2023-41904 | MEDIUM | 5.4 | 2.0% | Sep 27, 2023 | Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs. |
| CVE-2023-41888 | MEDIUM | 5.4 | 0.4% | Sep 27, 2023 | GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide... |
| CVE-2023-41861 | MEDIUM | 6.1 | 0.4% | Sep 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Restrict plugin <= 2.2.4 versions. |
| CVE-2023-41860 | MEDIUM | 6.1 | 0.3% | Sep 27, 2023 | Unauth. Cross-Site Scripting (XSS) vulnerability in TravelMap plugin <= 1.0.1 versions. |
| CVE-2023-41653 | MEDIUM | 6.1 | 0.4% | Sep 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0 versions. |
| CVE-2023-41323 | MEDIUM | 5.3 | 34.1% | Sep 27, 2023 | GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide... |
| CVE-2023-41321 | MEDIUM | 6.5 | 0.7% | Sep 27, 2023 | GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide... |
| CVE-2023-41312 | MEDIUM | 5.3 | 0.4% | Sep 27, 2023 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several ap... |
| CVE-2023-41311 | MEDIUM | 5.3 | 0.3% | Sep 27, 2023 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to ... |
| CVE-2023-41242 | MEDIUM | 4.8 | 0.3% | Sep 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hassan Ali Snap Pixel plugin <= 1.5.7 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now