2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5209 | MEDIUM | 4.8 | 0.5% | Nov 27, 2023 | The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its... |
| CVE-2023-4922 | CRITICAL | 9.8 | 15.7% | Nov 27, 2023 | The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter. |
| CVE-2023-4642 | MEDIUM | 5.9 | 0.4% | Nov 27, 2023 | The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple ... |
| CVE-2023-4514 | MEDIUM | 5.4 | 0.4% | Nov 27, 2023 | The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes befo... |
| CVE-2023-4297 | MEDIUM | 4.3 | 0.6% | Nov 27, 2023 | The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing ... |
| CVE-2023-4252 | MEDIUM | 5.3 | 0.5% | Nov 27, 2023 | The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attack... |
| CVE-2023-49047 | HIGH | 7.5 | 0.8% | Nov 27, 2023 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName. |
| CVE-2023-49042 | CRITICAL | 9.8 | 1.4% | Nov 27, 2023 | Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedSt... |
| CVE-2023-49040 | CRITICAL | 9.8 | 1.5% | Nov 27, 2023 | An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the f... |
| CVE-2023-49028 | MEDIUM | 5.4 | 0.8% | Nov 27, 2023 | Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitra... |
| CVE-2023-42000 | CRITICAL | 9.8 | 1.5% | Nov 27, 2023 | Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServl... |
| CVE-2023-41999 | CRITICAL | 9.8 | 1.4% | Nov 27, 2023 | An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a v... |
| CVE-2023-41998 | CRITICAL | 9.8 | 15.3% | Nov 27, 2023 | Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. ... |
| CVE-2023-2707 | MEDIUM | 4.8 | 0.4% | Nov 27, 2023 | The gAppointments WordPress plugin through 1.9.5.1 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2023-49046 | CRITICAL | 9.8 | 1.4% | Nov 27, 2023 | Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devNam... |
| CVE-2023-49043 | CRITICAL | 9.8 | 13.2% | Nov 27, 2023 | Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpaps... |
| CVE-2023-49029 | MEDIUM | 6.1 | 0.9% | Nov 27, 2023 | Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitra... |
| CVE-2023-41257 | HIGH | 8.8 | 1.6% | Nov 27, 2023 | A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially ... |
| CVE-2023-40194 | HIGH | 8.8 | 2.0% | Nov 27, 2023 | An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due ... |
| CVE-2023-39542 | HIGH | 8.8 | 3.3% | Nov 27, 2023 | A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted mal... |
| CVE-2023-38573 | HIGH | 8.8 | 1.9% | Nov 27, 2023 | A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field. A specially crafte... |
| CVE-2023-35985 | HIGH | 8.8 | 2.7% | Nov 27, 2023 | An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due ... |
| CVE-2023-32616 | HIGH | 8.8 | 1.8% | Nov 27, 2023 | A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles 3D annotations. A specially crafted J... |
| CVE-2023-31275 | HIGH | 7.8 | 1.7% | Nov 27, 2023 | An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elem... |
| CVE-2023-6287 | MEDIUM | 5.5 | 0.2% | Nov 27, 2023 | Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now