2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4434 | MEDIUM | 6.1 | 0.3% | Aug 20, 2023 | Missing Authorization in GitHub repository hamza417/inure prior to build88. |
| CVE-2023-2971 | MEDIUM | 6.5 | 0.4% | Aug 19, 2023 | Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files an... |
| CVE-2023-4433 | MEDIUM | 5.4 | 0.5% | Aug 19, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. |
| CVE-2023-4432 | MEDIUM | 6.1 | 0.5% | Aug 19, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. |
| CVE-2023-40037 | MEDIUM | 6.5 | 1.5% | Aug 18, 2023 | Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with co... |
| CVE-2023-4422 | MEDIUM | 4.8 | 0.6% | Aug 18, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. |
| CVE-2023-38911 | MEDIUM | 5.4 | 0.5% | Aug 18, 2023 | A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted pay... |
| CVE-2023-38910 | MEDIUM | 6.1 | 0.4% | Aug 18, 2023 | CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HT... |
| CVE-2023-27471 | MEDIUM | 5.5 | 0.2% | Aug 18, 2023 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect a... |
| CVE-2023-32130 | MEDIUM | 4.8 | 0.4% | Aug 18, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.6 versions. |
| CVE-2023-32122 | MEDIUM | 6.1 | 0.3% | Aug 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spiffy Plugins Spiffy Calendar plugin <= 4.9.3 versions. |
| CVE-2023-32109 | MEDIUM | 6.1 | 0.4% | Aug 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On line plugin <= 4.6.3 vers... |
| CVE-2023-32108 | MEDIUM | 6.1 | 0.4% | Aug 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On line plugin <= 4.6.3 vers... |
| CVE-2023-30499 | MEDIUM | 6.1 | 0.4% | Aug 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.72... |
| CVE-2023-29387 | MEDIUM | 5.4 | 0.4% | Aug 18, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Julien Crego Manager for Icomoon plugin <= 2.0 v... |
| CVE-2023-27576 | MEDIUM | 6.7 | 0.3% | Aug 18, 2023 | An issue was discovered in phpList before 3.6.14. Due to an access error, it was possible to manipulate and edit data of... |
| CVE-2023-32107 | MEDIUM | 6.1 | 0.4% | Aug 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image... |
| CVE-2023-32106 | MEDIUM | 6.1 | 0.4% | Aug 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Fahad Mahmood WP Docs plugin <= 1.9.9 versions. |
| CVE-2023-32105 | MEDIUM | 6.1 | 0.4% | Aug 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ollybach WPPizza – A Restaurant Plugin plugin <= 3.17.1 ve... |
| CVE-2023-32103 | MEDIUM | 5.4 | 0.4% | Aug 18, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Theme Palace TP Education plugin <= 4.4 versions... |
| CVE-2023-31232 | MEDIUM | 4.8 | 0.4% | Aug 18, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David Artiss Plugins List plugin <= 2.5 versions. |
| CVE-2023-31218 | MEDIUM | 6.1 | 0.2% | Aug 18, 2023 | Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPr... |
| CVE-2023-31228 | MEDIUM | 4.8 | 0.4% | Aug 18, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace... |
| CVE-2023-31094 | MEDIUM | 6.1 | 0.4% | Aug 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce plugin... |
| CVE-2023-30875 | MEDIUM | 4.8 | 0.4% | Aug 18, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in All My Web Needs Logo Scheduler plugin <= 1.2.0 versio... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now