2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-35783 | MEDIUM | 6.1 | 0.3% | Jun 16, 2023 | The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x before 4.6.6, and 5.x before 5.0.2 for TY... |
| CVE-2023-20885 | MEDIUM | 6.5 | 0.5% | Jun 16, 2023 | Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This... |
| CVE-2023-3294 | MEDIUM | 6.1 | 0.5% | Jun 16, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e1... |
| CVE-2023-26537 | MEDIUM | 4.8 | 0.4% | Jun 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nicolly WP No External Links plugin <= 1.0.2 versions. |
| CVE-2023-26527 | MEDIUM | 4.8 | 0.4% | Jun 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions. |
| CVE-2023-25974 | MEDIUM | 4.8 | 0.4% | Jun 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions. |
| CVE-2023-3293 | MEDIUM | 4.8 | 0.5% | Jun 16, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0. |
| CVE-2023-27420 | MEDIUM | 6.1 | 0.4% | Jun 16, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Arya Multipurpose theme <= 1.0.5 versions. |
| CVE-2023-26515 | MEDIUM | 4.8 | 0.4% | Jun 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ko Takagi Simple Slug Translate plugin <= 2.7.2 versio... |
| CVE-2023-33307 | MEDIUM | 6.5 | 0.6% | Jun 16, 2023 | A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 ... |
| CVE-2023-33306 | MEDIUM | 6.5 | 0.8% | Jun 16, 2023 | A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 a... |
| CVE-2023-2831 | MEDIUM | 6.5 | 0.7% | Jun 16, 2023 | Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Servi... |
| CVE-2023-2797 | MEDIUM | 6.5 | 0.5% | Jun 16, 2023 | Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting ... |
| CVE-2023-2793 | MEDIUM | 6.5 | 0.6% | Jun 16, 2023 | Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an at... |
| CVE-2023-2792 | MEDIUM | 6.5 | 0.6% | Jun 16, 2023 | Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a sp... |
| CVE-2023-2785 | MEDIUM | 4.3 | 0.6% | Jun 16, 2023 | Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to c... |
| CVE-2023-2791 | MEDIUM | 4.3 | 0.4% | Jun 16, 2023 | When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated... |
| CVE-2023-2788 | MEDIUM | 6.5 | 0.5% | Jun 16, 2023 | Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with adm... |
| CVE-2023-2787 | MEDIUM | 6.5 | 0.5% | Jun 16, 2023 | Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary po... |
| CVE-2023-2786 | MEDIUM | 4.3 | 0.4% | Jun 16, 2023 | Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post... |
| CVE-2023-2784 | MEDIUM | 6.5 | 0.3% | Jun 16, 2023 | Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowin... |
| CVE-2023-2783 | MEDIUM | 4.3 | 0.4% | Jun 16, 2023 | Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to... |
| CVE-2023-26541 | MEDIUM | 4.8 | 0.4% | Jun 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alexander Suess asMember plugin <= 1.5.4 versions. |
| CVE-2023-26013 | MEDIUM | 5.4 | 0.4% | Jun 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill Strong Testimonials plugin <= 3.0.2 vers... |
| CVE-2023-25963 | MEDIUM | 4.8 | 0.4% | Jun 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JoomSky JS Job Manager plugin <= 2.0.0 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now