2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40814 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field. |
| CVE-2023-40813 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Saved Search Creation. |
| CVE-2023-40812 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field. |
| CVE-2023-40810 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field. |
| CVE-2023-40809 | MEDIUM | 6.1 | 0.5% | Nov 18, 2023 | OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number. |
| CVE-2023-6187 | HIGH | 8.8 | 51.5% | Nov 18, 2023 | The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type vali... |
| CVE-2023-4214 | CRITICAL | 9.8 | 0.9% | Nov 18, 2023 | The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5... |
| CVE-2023-48017 | HIGH | 8.8 | 0.4% | Nov 18, 2023 | Dreamer_cms 4.1.3 is vulnerable to Cross Site Request Forgery (CSRF) via Add permissions to CSRF in Permission Managemen... |
| CVE-2023-48028 | CRITICAL | 9.8 | 1.1% | Nov 18, 2023 | kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an at... |
| CVE-2023-46402 | HIGH | 7.5 | 0.9% | Nov 18, 2023 | git-urls 1.0.0 allows ReDOS (Regular Expression Denial of Service) in urls.go. |
| CVE-2023-44796 | MEDIUM | 5.4 | 0.7% | Nov 18, 2023 | Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate ... |
| CVE-2023-43177 | CRITICAL | 9.8 | 81.8% | Nov 18, 2023 | CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes... |
| CVE-2023-48294 | MEDIUM | 4.3 | 0.7% | Nov 17, 2023 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo... |
| CVE-2023-48238 | HIGH | 7.5 | 0.3% | Nov 17, 2023 | joaquimserafim/json-web-token is a javascript library use to interact with JSON Web Tokens (JWT) which are a compact URL... |
| CVE-2023-46745 | HIGH | 7.5 | 0.6% | Nov 17, 2023 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo... |
| CVE-2023-48295 | MEDIUM | 5.4 | 0.6% | Nov 17, 2023 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo... |
| CVE-2023-6188 | CRITICAL | 9.8 | 1.0% | Nov 17, 2023 | A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown ... |
| CVE-2023-48185 | HIGH | 7.5 | 1.3% | Nov 17, 2023 | Directory Traversal vulnerability in TerraMaster v.s1.0 through v.2.295 allows a remote attacker to obtain sensitive inf... |
| CVE-2023-6179 | HIGH | 7.8 | 0.2% | Nov 17, 2023 | Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable... |
| CVE-2023-48025 | HIGH | 8.1 | 0.7% | Nov 17, 2023 | Liblisp through commit 4c65969 was discovered to contain a out-of-bounds-read vulnerability in unsigned get_length(lisp_... |
| CVE-2023-48024 | MEDIUM | 6.5 | 0.6% | Nov 17, 2023 | Liblisp through commit 4c65969 was discovered to contain a use-after-free vulnerability in void hash_destroy(hash_table_... |
| CVE-2023-44355 | MEDIUM | 4.3 | 47.2% | Nov 17, 2023 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Input Validation vu... |
| CVE-2023-44353 | CRITICAL | 9.8 | 80.2% | Nov 17, 2023 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted... |
| CVE-2023-44352 | MEDIUM | 6.1 | 84.8% | Nov 17, 2023 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by a reflected Cross-Site Scriptin... |
| CVE-2023-44351 | CRITICAL | 9.8 | 50.2% | Nov 17, 2023 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now