2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37489 | MEDIUM | 5.3 | 0.4% | Sep 12, 2023 | Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version ... |
| CVE-2023-32005 | MEDIUM | 5.3 | 1.2% | Sep 12, 2023 | A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the... |
| CVE-2023-38878 | MEDIUM | 6.1 | 0.6% | Sep 11, 2023 | A reflected cross-site scripting (XSS) vulnerability in DevCode OpenSTAManager versions 2.4.24 to 2.4.47 may allow a rem... |
| CVE-2023-35683 | MEDIUM | 5.5 | 0.2% | Sep 11, 2023 | In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injec... |
| CVE-2023-35680 | MEDIUM | 5.5 | 0.1% | Sep 11, 2023 | In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. Thi... |
| CVE-2023-35679 | MEDIUM | 5.5 | 0.1% | Sep 11, 2023 | In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead ... |
| CVE-2023-35677 | MEDIUM | 5.5 | 0.1% | Sep 11, 2023 | In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission c... |
| CVE-2023-35675 | MEDIUM | 5.5 | 0.1% | Sep 11, 2023 | In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files play... |
| CVE-2023-35671 | MEDIUM | 5.5 | 0.2% | Sep 11, 2023 | In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read th... |
| CVE-2023-35664 | MEDIUM | 5.5 | 0.1% | Sep 11, 2023 | In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. Th... |
| CVE-2023-4318 | MEDIUM | 4.3 | 0.2% | Sep 11, 2023 | The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers t... |
| CVE-2023-4307 | MEDIUM | 4.3 | 0.2% | Sep 11, 2023 | The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, ... |
| CVE-2023-4294 | MEDIUM | 6.1 | 0.7% | Sep 11, 2023 | The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing a... |
| CVE-2023-4270 | MEDIUM | 6.1 | 0.4% | Sep 11, 2023 | The Min Max Control WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting it back in th... |
| CVE-2023-4060 | MEDIUM | 4.8 | 0.4% | Sep 11, 2023 | The WP Adminify WordPress plugin before 3.1.6 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2023-4022 | MEDIUM | 4.8 | 0.4% | Sep 11, 2023 | The Herd Effects WordPress plugin before 5.2.3 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2023-41336 | MEDIUM | 6.5 | 0.5% | Sep 11, 2023 | ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could s... |
| CVE-2023-3510 | MEDIUM | 5.4 | 0.2% | Sep 11, 2023 | The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and i... |
| CVE-2023-3170 | MEDIUM | 4.8 | 0.4% | Sep 11, 2023 | The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, do... |
| CVE-2023-3169 | MEDIUM | 6.1 | 1.6% | Sep 11, 2023 | The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, do... |
| CVE-2023-2705 | MEDIUM | 6.1 | 0.4% | Sep 11, 2023 | The gAppointments WordPress plugin before 1.10.0 does not sanitise and escape a parameter before outputting it back in t... |
| CVE-2023-41103 | MEDIUM | 5.4 | 0.4% | Sep 11, 2023 | Interact 7.9.79.5 allows stored Cross-site Scripting (XSS) attacks in several locations, allowing an attacker to store a... |
| CVE-2023-40032 | MEDIUM | 5.5 | 0.2% | Sep 11, 2023 | libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libv... |
| CVE-2023-41609 | MEDIUM | 6.1 | 0.4% | Sep 11, 2023 | An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim us... |
| CVE-2023-41593 | MEDIUM | 5.4 | 0.8% | Sep 11, 2023 | Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now