2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1090 | MEDIUM | 4.8 | 0.5% | May 2, 2023 | The SMTP Mailing Queue WordPress plugin before 2.0.1 does not sanitise and escape some of its settings, which could allo... |
| CVE-2023-1021 | MEDIUM | 4.8 | 0.4% | May 2, 2023 | The amr ical events lists WordPress plugin through 6.6 does not sanitise and escape some of its settings, which could al... |
| CVE-2023-0891 | MEDIUM | 5.4 | 0.4% | May 2, 2023 | The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2023-2247 | MEDIUM | 5.3 | 0.4% | May 2, 2023 | In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function |
| CVE-2023-30639 | MEDIUM | 5.4 | 0.3% | May 1, 2023 | Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability. A remote authenticated maliciou... |
| CVE-2023-29681 | MEDIUM | 5.7 | 0.4% | May 1, 2023 | Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker ... |
| CVE-2023-29680 | MEDIUM | 5.7 | 0.4% | May 1, 2023 | Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attac... |
| CVE-2023-27108 | MEDIUM | 5.3 | 0.6% | May 1, 2023 | An issue was discovered in KaiOS 3.0. The pre-installed Communications application exposes a Web Activity that returns t... |
| CVE-2023-26987 | MEDIUM | 6.5 | 1.1% | May 1, 2023 | An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via craf... |
| CVE-2023-22924 | MEDIUM | 4.9 | 0.8% | May 1, 2023 | A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remot... |
| CVE-2023-22923 | MEDIUM | 6.5 | 0.8% | May 1, 2023 | A format string vulnerability in a binary of the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could all... |
| CVE-2023-22503 | MEDIUM | 5.3 | 0.8% | May 1, 2023 | Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of a... |
| CVE-2023-29643 | MEDIUM | 5.4 | 0.5% | May 1, 2023 | Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post fu... |
| CVE-2023-29641 | MEDIUM | 6.1 | 0.4% | May 1, 2023 | Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script ... |
| CVE-2023-29639 | MEDIUM | 5.4 | 0.4% | May 1, 2023 | Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML ... |
| CVE-2023-29638 | MEDIUM | 5.4 | 0.4% | May 1, 2023 | Cross Site Scripting (XSS) vulnerability in WinterChenS my-site before commit 3f0423da6d5200c7a46e200da145c1f54ee18548, ... |
| CVE-2023-29637 | MEDIUM | 6.1 | 0.4% | May 1, 2023 | Cross Site Scripting (XSS) vulnerability in Qbian61 forum-java, allows attackers to inject arbitrary web script or HTML ... |
| CVE-2023-29636 | MEDIUM | 5.4 | 0.4% | May 1, 2023 | Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML ... |
| CVE-2023-28092 | MEDIUM | 6.8 | 0.2% | May 1, 2023 | A potential security vulnerability has been identified in HPE ProLiant RL300 Gen11 Server. The vulnerability could resul... |
| CVE-2023-2428 | MEDIUM | 5.4 | 0.6% | Apr 30, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.13. |
| CVE-2023-2426 | MEDIUM | 5.5 | 0.4% | Apr 29, 2023 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499. |
| CVE-2023-2425 | MEDIUM | 4.8 | 0.6% | Apr 29, 2023 | A vulnerability was found in SourceCodester Simple Student Information System 1.0. It has been classified as problematic... |
| CVE-2023-30792 | MEDIUM | 6.1 | 0.4% | Apr 29, 2023 | Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link cl... |
| CVE-2023-2421 | MEDIUM | 6.1 | 0.6% | Apr 29, 2023 | A vulnerability classified as problematic has been found in Control iD RHiD 23.3.19.0. Affected is an unknown function o... |
| CVE-2023-2418 | MEDIUM | 5.9 | 0.7% | Apr 29, 2023 | A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now