2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49803 | HIGH | 7.5 | 0.3% | Dec 11, 2023 | @koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to version 5.0.0... |
| CVE-2023-49802 | MEDIUM | 6.1 | 0.7% | Dec 11, 2023 | The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-d... |
| CVE-2023-45292 | MEDIUM | 5.3 | 0.3% | Dec 11, 2023 | When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the fi... |
| CVE-2023-49796 | MEDIUM | 5.3 | 0.5% | Dec 11, 2023 | MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a limited file wr... |
| CVE-2023-49494 | MEDIUM | 6.1 | 1.2% | Dec 11, 2023 | DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component selec... |
| CVE-2023-49490 | MEDIUM | 6.1 | 0.4% | Dec 11, 2023 | XunRuiCMS v4.5.5 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admi... |
| CVE-2023-49488 | MEDIUM | 6.1 | 0.4% | Dec 11, 2023 | A cross-site scripting (XSS) vulnerability in Openfiler ESA v2.99.1 allows attackers to execute arbitrary web scripts or... |
| CVE-2023-6035 | HIGH | 8.8 | 0.9% | Dec 11, 2023 | The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an ... |
| CVE-2023-5955 | MEDIUM | 4.8 | 0.5% | Dec 11, 2023 | The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could all... |
| CVE-2023-5940 | MEDIUM | 4.8 | 0.4% | Dec 11, 2023 | The WP Not Login Hide (WPNLH) WordPress plugin through 1.0 does not sanitise and escape some of its settings, which coul... |
| CVE-2023-5907 | MEDIUM | 6.5 | 0.9% | Dec 11, 2023 | The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrat... |
| CVE-2023-5757 | MEDIUM | 4.8 | 0.5% | Dec 11, 2023 | The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2023-5750 | MEDIUM | 6.1 | 0.5% | Dec 11, 2023 | The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2023-5749 | MEDIUM | 6.1 | 0.6% | Dec 11, 2023 | The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the pa... |
| CVE-2023-6679 | MEDIUM | 5.5 | 0.3% | Dec 11, 2023 | A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Di... |
| CVE-2023-49795 | MEDIUM | 5.3 | 0.4% | Dec 11, 2023 | MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side req... |
| CVE-2023-48715 | MEDIUM | 5.4 | 0.5% | Dec 11, 2023 | Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.2.9... |
| CVE-2023-6538 | MEDIUM | 6.5 | 1.6% | Dec 11, 2023 | SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authe... |
| CVE-2023-6671 | HIGH | 8.8 | 0.2% | Dec 11, 2023 | A vulnerability has been discovered on OJS, that consists in a CSRF (Cross-Site Request Forgery) attack that forces an e... |
| CVE-2023-6194 | HIGH | 7.1 | 0.3% | Dec 11, 2023 | In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document typ... |
| CVE-2023-49418 | CRITICAL | 9.8 | 0.9% | Dec 11, 2023 | TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules. |
| CVE-2023-49417 | CRITICAL | 9.8 | 0.9% | Dec 11, 2023 | TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg. |
| CVE-2023-6186 | HIGH | 8.8 | 0.8% | Dec 11, 2023 | Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in m... |
| CVE-2023-6185 | HIGH | 8.8 | 1.0% | Dec 11, 2023 | Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attack... |
| CVE-2023-49964 | HIGH | 8.8 | 34.7% | Dec 11, 2023 | An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now