2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40779 | MEDIUM | 6.1 | 1.4% | Sep 14, 2023 | An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafte... |
| CVE-2023-4951 | MEDIUM | 4.8 | 0.3% | Sep 14, 2023 | A cross site scripting issue was discovered with the pagination function on the "Client-based Authentication Policy Conf... |
| CVE-2023-42178 | MEDIUM | 6.5 | 0.5% | Sep 14, 2023 | Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the log query module. |
| CVE-2023-38558 | MEDIUM | 5.5 | 0.2% | Sep 14, 2023 | A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Ad... |
| CVE-2023-42503 | MEDIUM | 5.5 | 0.5% | Sep 14, 2023 | Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.Thi... |
| CVE-2023-38206 | MEDIUM | 5.3 | 0.6% | Sep 14, 2023 | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improp... |
| CVE-2023-26141 | MEDIUM | 4.9 | 0.8% | Sep 14, 2023 | Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the... |
| CVE-2023-4948 | MEDIUM | 4.3 | 0.3% | Sep 14, 2023 | The WooCommerce CVR Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2023-4945 | MEDIUM | 5.4 | 0.5% | Sep 14, 2023 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in... |
| CVE-2023-4944 | MEDIUM | 5.4 | 0.4% | Sep 14, 2023 | The Awesome Weather Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' short... |
| CVE-2023-4841 | MEDIUM | 5.4 | 0.5% | Sep 14, 2023 | The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in ... |
| CVE-2023-41162 | MEDIUM | 6.1 | 0.4% | Sep 13, 2023 | A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to... |
| CVE-2023-41158 | MEDIUM | 5.4 | 0.4% | Sep 13, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers... |
| CVE-2023-41155 | MEDIUM | 5.4 | 0.4% | Sep 13, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the mail forwarding and replies tab in Webmin and Usermin 2.000 all... |
| CVE-2023-41154 | MEDIUM | 5.4 | 0.4% | Sep 13, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the scheduled cron jobs tab in Usermin 2.000 allows remote attacker... |
| CVE-2023-41152 | MEDIUM | 5.4 | 0.4% | Sep 13, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers... |
| CVE-2023-40617 | MEDIUM | 6.1 | 0.5% | Sep 13, 2023 | A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execut... |
| CVE-2023-4568 | MEDIUM | 6.5 | 3.6% | Sep 13, 2023 | PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to... |
| CVE-2023-42468 | MEDIUM | 5.3 | 0.9% | Sep 13, 2023 | The com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls ... |
| CVE-2023-3588 | MEDIUM | 5.4 | 0.3% | Sep 13, 2023 | A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic ... |
| CVE-2023-4155 | MEDIUM | 5.6 | 0.2% | Sep 13, 2023 | A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-S... |
| CVE-2023-3301 | MEDIUM | 5.6 | 0.3% | Sep 13, 2023 | A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared... |
| CVE-2023-3280 | MEDIUM | 5.5 | 0.3% | Sep 13, 2023 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user ... |
| CVE-2023-3255 | MEDIUM | 6.5 | 1.4% | Sep 13, 2023 | A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lea... |
| CVE-2023-20233 | MEDIUM | 6.5 | 0.3% | Sep 13, 2023 | A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticat... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now