2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32503 | MEDIUM | 6.1 | 0.4% | Aug 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GTmetrix GTmetrix for WordPress plugin <= 0.4.6 versions. |
| CVE-2023-29099 | MEDIUM | 5.4 | 0.4% | Aug 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Elegant themes Divi theme <= 4.20.2 versions. |
| CVE-2023-27422 | MEDIUM | 4.8 | 0.4% | Aug 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NsThemes NS Coupon To Become Customer plugin <= 1.2.2 ... |
| CVE-2023-27421 | MEDIUM | 6.1 | 0.4% | Aug 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Everest News theme <= 1.1.0 versions. |
| CVE-2023-27416 | MEDIUM | 4.8 | 0.4% | Aug 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Decon Digital Decon WP SMS plugin <= 1.1 versions. |
| CVE-2023-27412 | MEDIUM | 6.1 | 0.4% | Aug 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Mocho Blog theme <= 1.0.4 versions. |
| CVE-2023-38532 | MEDIUM | 5.5 | 0.2% | Aug 8, 2023 | A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0... |
| CVE-2023-21647 | MEDIUM | 6.5 | 0.3% | Aug 8, 2023 | Information disclosure in Bluetooth when an GATT packet is received due to improper input validation. |
| CVE-2023-3569 | MEDIUM | 4.9 | 1.0% | Aug 8, 2023 | In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior... |
| CVE-2023-39440 | MEDIUM | 4.4 | 0.1% | Aug 8, 2023 | In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain sp... |
| CVE-2023-39437 | MEDIUM | 5.4 | 0.3% | Aug 8, 2023 | SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or ap... |
| CVE-2023-39436 | MEDIUM | 5.8 | 0.4% | Aug 8, 2023 | SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker t... |
| CVE-2023-37492 | MEDIUM | 6.5 | 0.4% | Aug 8, 2023 | SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASI... |
| CVE-2023-37488 | MEDIUM | 6.1 | 0.3% | Aug 8, 2023 | In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, ... |
| CVE-2023-37487 | MEDIUM | 5.3 | 0.4% | Aug 8, 2023 | SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain op... |
| CVE-2023-37484 | MEDIUM | 5.3 | 0.4% | Aug 8, 2023 | SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user prov... |
| CVE-2023-36926 | MEDIUM | 5.3 | 0.4% | Aug 8, 2023 | Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumente... |
| CVE-2023-39527 | MEDIUM | 6.1 | 0.4% | Aug 7, 2023 | PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to ... |
| CVE-2023-39363 | MEDIUM | 5.9 | 0.7% | Aug 7, 2023 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In versions 0.2.15, 0.2.16 and 0.3.0... |
| CVE-2023-38924 | MEDIUM | 6.5 | 0.6% | Aug 7, 2023 | Netgear DGN3500 1.1.00.37 was discovered to contain a buffer overflow via the http_password parameter at setup.cgi. |
| CVE-2023-36054 | MEDIUM | 6.5 | 2.1% | Aug 7, 2023 | lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized poin... |
| CVE-2023-38157 | MEDIUM | 6.5 | 2.5% | Aug 7, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2023-38045 | MEDIUM | 6.1 | 0.3% | Aug 7, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneV... |
| CVE-2023-3671 | MEDIUM | 6.1 | 0.4% | Aug 7, 2023 | The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters... |
| CVE-2023-3650 | MEDIUM | 4.8 | 0.6% | Aug 7, 2023 | The Bubble Menu WordPress plugin before 3.0.5 does not sanitize and escape some of its settings, which could allow high-... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now