2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27429 | MEDIUM | 4.8 | 0.4% | Jun 21, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Automattic - Jetpack CRM team Jetpack CRM plugin <= 5.... |
| CVE-2023-27414 | MEDIUM | 6.1 | 0.4% | Jun 21, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Popup Box Team Popup box plugin <= 3.4.4 versions. |
| CVE-2023-27450 | MEDIUM | 6.1 | 0.4% | Jun 21, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.29.2 versio... |
| CVE-2023-27443 | MEDIUM | 5.4 | 0.4% | Jun 21, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Grant Kimball Simple Vimeo Shortcode plugin <= 2... |
| CVE-2023-27439 | MEDIUM | 4.8 | 0.4% | Jun 21, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gl_SPICE New Adman plugin <= 1.6.8 versions. |
| CVE-2023-3220 | MEDIUM | 5.5 | 0.2% | Jun 20, 2023 | An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_... |
| CVE-2023-35095 | MEDIUM | 4.8 | 0.4% | Jun 20, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Flothemes Flo Forms – Easy Drag & Drop Form Builder pl... |
| CVE-2023-34597 | MEDIUM | 6.5 | 0.6% | Jun 20, 2023 | A vulnerability in Fibaro Motion Sensor firmware v3.4 allows attackers to cause a Denial of Service (DoS) via a crafted ... |
| CVE-2023-34596 | MEDIUM | 6.5 | 0.6% | Jun 20, 2023 | A vulnerability in Aeotec WallMote Switch firmware v2.3 allows attackers to cause a Denial of Service (DoS) via a crafte... |
| CVE-2023-33495 | MEDIUM | 6.1 | 0.5% | Jun 20, 2023 | Craft CMS through 4.4.9 is vulnerable to HTML Injection. |
| CVE-2023-35098 | MEDIUM | 6.1 | 0.4% | Jun 20, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 v... |
| CVE-2023-35097 | MEDIUM | 6.1 | 0.4% | Jun 20, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Internet Marketing Dojo WP Affiliate Links plugin <= 0.1.1... |
| CVE-2023-35882 | MEDIUM | 5.4 | 0.4% | Jun 20, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor Super Socializer plugin <= 7.13.52 ... |
| CVE-2023-35878 | MEDIUM | 4.8 | 0.4% | Jun 20, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Vadym K. Extra User Details plugin <= 0.5 versions. |
| CVE-2023-26435 | MEDIUM | 5 | 0.8% | Jun 20, 2023 | It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT doc... |
| CVE-2023-26434 | MEDIUM | 4.3 | 1.1% | Jun 20, 2023 | When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. At... |
| CVE-2023-26433 | MEDIUM | 4.3 | 1.1% | Jun 20, 2023 | When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. At... |
| CVE-2023-26432 | MEDIUM | 4.3 | 1.1% | Jun 20, 2023 | When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. At... |
| CVE-2023-26431 | MEDIUM | 4.3 | 0.8% | Jun 20, 2023 | IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers wit... |
| CVE-2023-26429 | MEDIUM | 5.3 | 0.8% | Jun 20, 2023 | Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected c... |
| CVE-2023-26428 | MEDIUM | 6.5 | 1.0% | Jun 20, 2023 | Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same con... |
| CVE-2023-35884 | MEDIUM | 6.1 | 0.4% | Jun 20, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions. |
| CVE-2023-3315 | MEDIUM | 4.3 | 0.5% | Jun 19, 2023 | Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission ... |
| CVE-2023-32659 | MEDIUM | 6.1 | 0.4% | Jun 19, 2023 | SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an at... |
| CVE-2023-3022 | MEDIUM | 5.5 | 0.2% | Jun 19, 2023 | A flaw was found in the IPv6 module of the Linux kernel. The arg.result was not used consistently in fib6_rule_lookup, s... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now