2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23563 | MEDIUM | 6.5 | 0.9% | Aug 22, 2023 | An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to obtain sensitive database c... |
| CVE-2023-38909 | MEDIUM | 6.5 | 0.8% | Aug 22, 2023 | An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, a... |
| CVE-2023-38908 | MEDIUM | 6.5 | 0.5% | Aug 22, 2023 | An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, a... |
| CVE-2023-38906 | MEDIUM | 6.5 | 0.5% | Aug 22, 2023 | An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200... |
| CVE-2023-4303 | MEDIUM | 6.1 | 0.4% | Aug 21, 2023 | Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in ... |
| CVE-2023-4302 | MEDIUM | 4.3 | 0.3% | Aug 21, 2023 | A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission t... |
| CVE-2023-4301 | MEDIUM | 5.4 | 0.2% | Aug 21, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers to conn... |
| CVE-2023-4459 | MEDIUM | 5.5 | 0.2% | Aug 21, 2023 | A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking s... |
| CVE-2023-4417 | MEDIUM | 6.5 | 0.4% | Aug 21, 2023 | Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier ... |
| CVE-2023-4456 | MEDIUM | 6.5 | 0.5% | Aug 21, 2023 | A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This is... |
| CVE-2023-3954 | MEDIUM | 6.1 | 0.4% | Aug 21, 2023 | The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before... |
| CVE-2023-3936 | MEDIUM | 6.1 | 0.9% | Aug 21, 2023 | The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the ... |
| CVE-2023-3667 | MEDIUM | 4.8 | 0.4% | Aug 21, 2023 | The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2023-3366 | MEDIUM | 4.3 | 0.2% | Aug 21, 2023 | The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipme... |
| CVE-2023-39094 | MEDIUM | 5.4 | 0.4% | Aug 21, 2023 | Cross Site Scripting vulnerability in ZeroWdd studentmanager v.1.0 allows a remote attacker to execute arbitrary code vi... |
| CVE-2023-3481 | MEDIUM | 6.1 | 0.1% | Aug 21, 2023 | Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XS... |
| CVE-2023-4455 | MEDIUM | 6.5 | 0.3% | Aug 21, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. |
| CVE-2023-4454 | MEDIUM | 5.7 | 0.2% | Aug 21, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. |
| CVE-2023-4453 | MEDIUM | 5.4 | 0.5% | Aug 21, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8. |
| CVE-2023-40068 | MEDIUM | 5.4 | 1.5% | Aug 21, 2023 | Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro vers... |
| CVE-2023-39543 | MEDIUM | 6.1 | 0.5% | Aug 21, 2023 | Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior ... |
| CVE-2023-4439 | MEDIUM | 5.3 | 0.4% | Aug 20, 2023 | A vulnerability was found in SourceCodester Card Holder Management System 1.0 and classified as problematic. Affected by... |
| CVE-2023-36674 | MEDIUM | 5.3 | 0.6% | Aug 20, 2023 | An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40... |
| CVE-2023-4451 | MEDIUM | 6.1 | 2.3% | Aug 20, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. |
| CVE-2023-4435 | MEDIUM | 5.5 | 0.4% | Aug 20, 2023 | Improper Input Validation in GitHub repository hamza417/inure prior to build88. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now