2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4258 | MEDIUM | 6.5 | 0.5% | Sep 25, 2023 | In Bluetooth mesh implementation If provisionee has a public key that is sent OOB then during provisioning it can be sen... |
| CVE-2023-43326 | MEDIUM | 6.1 | 1.6% | Sep 25, 2023 | A reflected cross-site scripting (XSS) vulnerability exisits in multiple url of mooSocial v3.1.8 allows attackers to ste... |
| CVE-2023-43132 | MEDIUM | 6.5 | 0.6% | Sep 25, 2023 | szvone vmqphp <=1.13 is vulnerable to SQL Injection. Unauthorized remote users can use sql injection attacks to obtain t... |
| CVE-2023-42426 | MEDIUM | 6.1 | 1.1% | Sep 25, 2023 | Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary co... |
| CVE-2023-43458 | MEDIUM | 5.4 | 0.5% | Sep 25, 2023 | Cross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrar... |
| CVE-2023-43319 | MEDIUM | 6.1 | 0.4% | Sep 25, 2023 | Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arb... |
| CVE-2023-42817 | MEDIUM | 5.4 | 0.3% | Sep 25, 2023 | Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from ... |
| CVE-2023-41871 | MEDIUM | 6.1 | 0.3% | Sep 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Poll Maker Team Poll Maker plugin <= 4.7.0 versions. |
| CVE-2023-41868 | MEDIUM | 6.1 | 0.3% | Sep 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ram Ratan Maurya, Codestag StagTools plugin <= 2.3.7 versi... |
| CVE-2023-41867 | MEDIUM | 6.1 | 0.3% | Sep 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AcyMailing Newsletter Team AcyMailing plugin <= 8.6.2 vers... |
| CVE-2023-41863 | MEDIUM | 6.1 | 0.3% | Sep 25, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Pepro Dev. Group PeproDev CF7 Database plugin <= 1.7.0 versio... |
| CVE-2023-5166 | MEDIUM | 6.5 | 0.7% | Sep 25, 2023 | Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desk... |
| CVE-2023-5158 | MEDIUM | 5.5 | 0.2% | Sep 25, 2023 | A flaw was found in vringh_kiov_advance in drivers/vhost/vringh.c in the host side of a virtio ring in the Linux Kernel.... |
| CVE-2023-4892 | MEDIUM | 4.6 | 0.4% | Sep 25, 2023 | Teedy v1.11 has a vulnerability in its text editor that allows events to be executed in HTML tags that an attacker coul... |
| CVE-2023-4631 | MEDIUM | 5.3 | 0.6% | Sep 25, 2023 | The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of ... |
| CVE-2023-4549 | MEDIUM | 6.1 | 0.6% | Sep 25, 2023 | The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For... |
| CVE-2023-4502 | MEDIUM | 4.8 | 0.4% | Sep 25, 2023 | The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings,... |
| CVE-2023-4476 | MEDIUM | 6.1 | 0.4% | Sep 25, 2023 | The Locatoraid Store Locator WordPress plugin before 3.9.24 does not sanitise and escape the lpr-search parameter before... |
| CVE-2023-4281 | MEDIUM | 5.3 | 0.6% | Sep 25, 2023 | This Activity Log WordPress plugin before 2.8.8 retrieves client IP addresses from potentially untrusted headers, allowi... |
| CVE-2023-4148 | MEDIUM | 6.1 | 0.8% | Sep 25, 2023 | The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputti... |
| CVE-2023-43339 | MEDIUM | 6.1 | 0.6% | Sep 25, 2023 | Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via... |
| CVE-2023-3226 | MEDIUM | 4.8 | 0.4% | Sep 25, 2023 | The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2023-43456 | MEDIUM | 5.4 | 0.7% | Sep 25, 2023 | Cross Site Scripting vulnerability in Service Provider Management System v.1.0 allows a remote attacker to execute arbit... |
| CVE-2023-43256 | MEDIUM | 6.5 | 0.7% | Sep 25, 2023 | A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the ... |
| CVE-2023-41295 | MEDIUM | 5.3 | 0.2% | Sep 25, 2023 | Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerabili... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now