2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34916 | MEDIUM | 6.1 | 0.4% | Jul 31, 2023 | Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java. |
| CVE-2023-38311 | MEDIUM | 5.4 | 0.5% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the System ... |
| CVE-2023-38310 | MEDIUM | 5.4 | 0.5% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the configu... |
| CVE-2023-38309 | MEDIUM | 6.1 | 0.6% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the pack... |
| CVE-2023-38308 | MEDIUM | 6.1 | 0.6% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Cross-Site Scripting (XSS) vulnerability was discovered in the HTTP Tunnel fu... |
| CVE-2023-38307 | MEDIUM | 5.4 | 0.4% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users a... |
| CVE-2023-38306 | MEDIUM | 6.1 | 0.5% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file up... |
| CVE-2023-38305 | MEDIUM | 6.1 | 0.5% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. The download functionality allows an attacker to exploit a Cross-Site Scripting... |
| CVE-2023-38304 | MEDIUM | 5.4 | 0.4% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users a... |
| CVE-2023-38303 | MEDIUM | 5.4 | 0.7% | Jul 31, 2023 | An issue was discovered in Webmin 2.021. One can exploit a stored Cross-Site Scripting (XSS) attack to achieve Remote Co... |
| CVE-2023-35792 | MEDIUM | 6.1 | 0.3% | Jul 31, 2023 | Vound Intella Connect 2.6.0.3 is vulnerable to stored Cross-site Scripting (XSS). |
| CVE-2023-35791 | MEDIUM | 6.1 | 0.3% | Jul 31, 2023 | Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability. |
| CVE-2023-34872 | MEDIUM | 5.5 | 0.9% | Jul 31, 2023 | A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (... |
| CVE-2023-3508 | MEDIUM | 6.5 | 0.3% | Jul 31, 2023 | The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which ... |
| CVE-2023-3507 | MEDIUM | 6.5 | 0.3% | Jul 31, 2023 | The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could ... |
| CVE-2023-3345 | MEDIUM | 6.5 | 1.9% | Jul 31, 2023 | The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoi... |
| CVE-2023-3292 | MEDIUM | 6.1 | 0.4% | Jul 31, 2023 | The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outp... |
| CVE-2023-3134 | MEDIUM | 6.1 | 3.5% | Jul 31, 2023 | The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form field... |
| CVE-2023-3130 | MEDIUM | 4.8 | 0.4% | Jul 31, 2023 | The Short URL WordPress plugin before 1.6.5 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-0602 | MEDIUM | 6.1 | 0.9% | Jul 31, 2023 | The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the... |
| CVE-2023-34360 | MEDIUM | 5.4 | 0.4% | Jul 31, 2023 | A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U run... |
| CVE-2023-24971 | MEDIUM | 6.5 | 0.7% | Jul 31, 2023 | IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to caus... |
| CVE-2023-22595 | MEDIUM | 5.4 | 0.3% | Jul 31, 2023 | IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 are vulnerable to cross-sit... |
| CVE-2023-4007 | MEDIUM | 5.4 | 0.4% | Jul 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.16. |
| CVE-2023-35016 | MEDIUM | 6.5 | 0.9% | Jul 31, 2023 | IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the syste... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now