2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5153 | MEDIUM | 6.5 | 1.7% | Sep 25, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-8000 up to 20... |
| CVE-2023-5152 | MEDIUM | 6.5 | 7.0% | Sep 25, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000 and... |
| CVE-2023-41872 | MEDIUM | 6.1 | 0.3% | Sep 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xtemos WoodMart plugin <= 7.2.4 versions. |
| CVE-2023-41949 | MEDIUM | 4.8 | 0.3% | Sep 25, 2023 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Avirtum iFolders plugin <= 1.5.0 versions. |
| CVE-2023-41948 | MEDIUM | 4.8 | 0.3% | Sep 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christoph Rado Cookie Notice & Consent plugin <= 1.6.0... |
| CVE-2023-41874 | MEDIUM | 6.1 | 0.4% | Sep 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce plugin... |
| CVE-2023-5142 | MEDIUM | 5.3 | 2.3% | Sep 24, 2023 | A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, ... |
| CVE-2023-1636 | MEDIUM | 5 | 0.5% | Sep 24, 2023 | A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that ut... |
| CVE-2023-1633 | MEDIUM | 5.5 | 0.2% | Sep 24, 2023 | A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the con... |
| CVE-2023-1625 | MEDIUM | 5 | 0.7% | Sep 24, 2023 | An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the... |
| CVE-2023-5134 | MEDIUM | 4.3 | 0.4% | Sep 23, 2023 | The Easy Registration Forms for WordPress is vulnerable to Information Disclosure via the 'erforms_user_meta' shortcode ... |
| CVE-2023-5125 | MEDIUM | 5.4 | 0.4% | Sep 23, 2023 | The Contact Form by FormGet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formget' shortcode in... |
| CVE-2023-43640 | MEDIUM | 6.5 | 0.5% | Sep 22, 2023 | TaxonWorks is a web-based workbench designed for taxonomists and biodiversity scientists. Prior to version 0.34.0, a SQL... |
| CVE-2023-42812 | MEDIUM | 4.3 | 0.3% | Sep 22, 2023 | Galaxy is an open-source platform for FAIR data analysis. Prior to version 22.05, Galaxy is vulnerable to server-side re... |
| CVE-2023-42811 | MEDIUM | 5.5 | 0.3% | Sep 22, 2023 | aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES... |
| CVE-2023-23766 | MEDIUM | 6.5 | 0.6% | Sep 22, 2023 | An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displa... |
| CVE-2023-4774 | MEDIUM | 5.4 | 0.5% | Sep 22, 2023 | The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp-piwik... |
| CVE-2023-4716 | MEDIUM | 5.4 | 0.5% | Sep 22, 2023 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shor... |
| CVE-2023-43782 | MEDIUM | 5.5 | 0.3% | Sep 22, 2023 | Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if ... |
| CVE-2023-43771 | MEDIUM | 5.5 | 0.2% | Sep 22, 2023 | In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program. |
| CVE-2023-43770 | MEDIUM | 6.1 | 56.9% | Sep 22, 2023 | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft... |
| CVE-2023-43090 | MEDIUM | 5.5 | 0.3% | Sep 22, 2023 | A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows... |
| CVE-2023-43763 | MEDIUM | 6.1 | 0.3% | Sep 22, 2023 | Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint. This affects WithSecure Policy Manag... |
| CVE-2023-41616 | MEDIUM | 4.8 | 0.4% | Sep 21, 2023 | A reflected cross-site scripting (XSS) vulnerability in the Search Student function of Student Management System v1.2.3 ... |
| CVE-2023-41614 | MEDIUM | 4.8 | 0.4% | Sep 21, 2023 | A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allow... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now