2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3586 | MEDIUM | 5.4 | 0.2% | Jul 17, 2023 | Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, re... |
| CVE-2023-3585 | MEDIUM | 4.3 | 0.4% | Jul 17, 2023 | Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially... |
| CVE-2023-3582 | MEDIUM | 4.3 | 0.3% | Jul 17, 2023 | Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privileged authenticated ... |
| CVE-2023-3577 | MEDIUM | 4.3 | 0.3% | Jul 17, 2023 | Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an... |
| CVE-2023-36656 | MEDIUM | 5.4 | 1.0% | Jul 17, 2023 | Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute ... |
| CVE-2023-35818 | MEDIUM | 6.8 | 0.2% | Jul 17, 2023 | An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker ... |
| CVE-2023-31853 | MEDIUM | 6.1 | 0.4% | Jul 17, 2023 | Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon paramet... |
| CVE-2023-31851 | MEDIUM | 6.1 | 0.4% | Jul 17, 2023 | Cudy LT400 1.13.4 is has a cross-site scripting (XSS) vulnerability in /cgi-bin/luci/admin/network/wireless/status via t... |
| CVE-2023-3245 | MEDIUM | 4.8 | 0.4% | Jul 17, 2023 | The Floating Chat Widget WordPress plugin before 3.1.2 does not sanitise and escape some of its settings, which could al... |
| CVE-2023-3182 | MEDIUM | 6.1 | 0.4% | Jul 17, 2023 | The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2023-3041 | MEDIUM | 6.1 | 0.4% | Jul 17, 2023 | The Autochat Automatic Conversation WordPress plugin through 1.1.7 does not sanitise and escape user input before output... |
| CVE-2023-31852 | MEDIUM | 6.1 | 0.6% | Jul 17, 2023 | Cudy LT400 1.13.4 is vulnerable to Cross Site Scripting (XSS) in cgi-bin/luci/admin/network/wireless/config via the ifac... |
| CVE-2023-2960 | MEDIUM | 6.1 | 0.3% | Jul 17, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliva Expertise Ol... |
| CVE-2023-2701 | MEDIUM | 6.1 | 0.5% | Jul 17, 2023 | The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, lea... |
| CVE-2023-2579 | MEDIUM | 5.4 | 1.1% | Jul 17, 2023 | The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow use... |
| CVE-2023-2143 | MEDIUM | 5.4 | 0.3% | Jul 17, 2023 | The Enable SVG, WebP & ICO Upload WordPress plugin through 1.0.3 does not sanitize SVG file contents, leading to a Cross... |
| CVE-2023-1893 | MEDIUM | 6.1 | 0.7% | Jul 17, 2023 | The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the... |
| CVE-2023-0439 | MEDIUM | 5.4 | 0.3% | Jul 17, 2023 | The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripti... |
| CVE-2023-34036 | MEDIUM | 5.3 | 0.4% | Jul 17, 2023 | Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious f... |
| CVE-2023-3700 | MEDIUM | 4.3 | 0.4% | Jul 17, 2023 | Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| CVE-2023-35012 | MEDIUM | 6.7 | 0.2% | Jul 17, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a... |
| CVE-2023-35901 | MEDIUM | 5.3 | 0.4% | Jul 17, 2023 | IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation... |
| CVE-2023-33857 | MEDIUM | 5.3 | 0.6% | Jul 17, 2023 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially craf... |
| CVE-2023-3691 | MEDIUM | 6.1 | 0.5% | Jul 16, 2023 | A vulnerability, which was classified as problematic, was found in layui up to v2.8.0-rc.16. This affects an unknown par... |
| CVE-2023-3685 | MEDIUM | 5.4 | 0.3% | Jul 16, 2023 | A vulnerability was found in Nesote Inout Search Engine AI Edition 1.1. It has been classified as problematic. This affe... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now