2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5119 | MEDIUM | 4.8 | 0.5% | Nov 20, 2023 | The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission s... |
| CVE-2023-4970 | MEDIUM | 4.8 | 0.4% | Nov 20, 2023 | The PubyDoc WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2023-4824 | HIGH | 8.8 | 0.4% | Nov 20, 2023 | The WooHoo Newspaper Magazine theme does not have CSRF check in place when updating its settings, which could allow atta... |
| CVE-2023-4808 | MEDIUM | 4.8 | 0.4% | Nov 20, 2023 | The WP Post Popup WordPress plugin through 3.7.3 does not sanitise and escape some of its inputs, which could allow high... |
| CVE-2023-4799 | MEDIUM | 5.4 | 0.4% | Nov 20, 2023 | The Magic Embeds WordPress plugin before 3.1.2 does not validate and escape some of its shortcode attributes before outp... |
| CVE-2023-48309 | MEDIUM | 5.3 | 0.7% | Nov 20, 2023 | NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the defau... |
| CVE-2023-48300 | MEDIUM | 5.4 | 0.5% | Nov 20, 2023 | The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored ... |
| CVE-2023-48293 | HIGH | 8.8 | 0.4% | Nov 20, 2023 | The XWiki Admin Tools Application provides tools to help the administration of XWiki. Prior to version 4.5.1, a cross-si... |
| CVE-2023-38885 | HIGH | 8.8 | 0.4% | Nov 20, 2023 | OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole ap... |
| CVE-2023-38884 | HIGH | 7.5 | 0.9% | Nov 20, 2023 | An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows ... |
| CVE-2023-38883 | MEDIUM | 6.1 | 0.6% | Nov 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic all... |
| CVE-2023-38882 | MEDIUM | 6.1 | 0.6% | Nov 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic all... |
| CVE-2023-38881 | MEDIUM | 6.1 | 0.6% | Nov 20, 2023 | A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic all... |
| CVE-2023-38880 | CRITICAL | 9.8 | 1.0% | Nov 20, 2023 | The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database b... |
| CVE-2023-38879 | HIGH | 7.5 | 3.7% | Nov 20, 2023 | The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a direc... |
| CVE-2023-48292 | HIGH | 8.8 | 22.9% | Nov 20, 2023 | The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior ... |
| CVE-2023-48241 | HIGH | 7.5 | 72.8% | Nov 20, 2023 | XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, a... |
| CVE-2023-48240 | HIGH | 8.8 | 0.7% | Nov 20, 2023 | XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents a... |
| CVE-2023-48223 | MEDIUM | 5.9 | 0.7% | Nov 20, 2023 | fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does not proper... |
| CVE-2023-48221 | HIGH | 8.8 | 0.9% | Nov 20, 2023 | wire-avs provides Audio, Visual, and Signaling (AVS) functionality sure the secure messaging software Wire. Prior to ver... |
| CVE-2023-48218 | MEDIUM | 5.3 | 0.6% | Nov 20, 2023 | The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3.... |
| CVE-2023-35762 | CRITICAL | 9.8 | 1.7% | Nov 20, 2023 | Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could... |
| CVE-2023-29155 | CRITICAL | 9.8 | 0.9% | Nov 20, 2023 | Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system ... |
| CVE-2023-36013 | MEDIUM | 6.5 | 1.4% | Nov 20, 2023 | PowerShell Information Disclosure Vulnerability |
| CVE-2023-6197 | MEDIUM | 5.4 | 0.2% | Nov 20, 2023 | The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now