2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34375 | MEDIUM | 6.1 | 0.4% | Nov 16, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web SEO by 10Web plugin <= 1.2.9 versions. |
| CVE-2023-32957 | MEDIUM | 4.8 | 0.4% | Nov 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dazzlersoft Team Members Showcase plugin <= 1.3.4 vers... |
| CVE-2023-32796 | MEDIUM | 6.1 | 0.4% | Nov 16, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in MingoCommerce WooCommerce Product Enquiry plugin <= 2.3.4 ver... |
| CVE-2023-28621 | MEDIUM | 6.1 | 0.4% | Nov 16, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wishfulthemes Rais... |
| CVE-2023-48134 | HIGH | 7.5 | 0.7% | Nov 16, 2023 | nagayama_copabowl Line 13.6.1 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. |
| CVE-2023-47512 | MEDIUM | 6.1 | 0.4% | Nov 16, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3... |
| CVE-2023-47511 | MEDIUM | 4.8 | 0.4% | Nov 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SO WP Pinyin Slugs plugin <= 2.3.0 versions. |
| CVE-2023-47509 | MEDIUM | 6.1 | 0.4% | Nov 16, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ioannup Edit WooCommerce Templates plugin <= 1.1.1 version... |
| CVE-2023-47508 | MEDIUM | 6.1 | 0.4% | Nov 16, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Averta Master Slider Pro plugin <= 3.6.5 versions. |
| CVE-2023-47245 | MEDIUM | 4.8 | 0.4% | Nov 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Viewer plugin <= 1.7 versions. |
| CVE-2023-47242 | MEDIUM | 5.4 | 0.4% | Nov 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.... |
| CVE-2023-47240 | MEDIUM | 5.4 | 0.4% | Nov 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Codeboxr CBX Map for Google Map & OpenStreetMap ... |
| CVE-2023-47239 | MEDIUM | 5.4 | 0.4% | Nov 16, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Paterson Easy PayPal Shopping Cart plugin ... |
| CVE-2023-6176 | MEDIUM | 4.7 | 0.3% | Nov 16, 2023 | A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functional... |
| CVE-2023-48056 | HIGH | 7.5 | 0.5% | Nov 16, 2023 | PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerabil... |
| CVE-2023-48055 | HIGH | 7.5 | 0.4% | Nov 16, 2023 | SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the dis... |
| CVE-2023-48054 | HIGH | 7.4 | 0.3% | Nov 16, 2023 | Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host... |
| CVE-2023-48053 | HIGH | 7.5 | 0.4% | Nov 16, 2023 | Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerabilit... |
| CVE-2023-48052 | HIGH | 7.4 | 0.3% | Nov 16, 2023 | Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and... |
| CVE-2023-47514 | MEDIUM | 6.1 | 0.4% | Nov 16, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in lawrenceowen, gcubero, acunnningham, fmahmood Star CloudPR... |
| CVE-2023-6038 | HIGH | 7.5 | 4.3% | Nov 16, 2023 | A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to re... |
| CVE-2023-6022 | HIGH | 8.8 | 0.4% | Nov 16, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository prefecthq/prefect prior to 2.16.5. |
| CVE-2023-6021 | HIGH | 7.5 | 37.1% | Nov 16, 2023 | LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed... |
| CVE-2023-6019 | CRITICAL | 9.8 | 74.6% | Nov 16, 2023 | A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system r... |
| CVE-2023-6017 | HIGH | 7.1 | 0.9% | Nov 16, 2023 | H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now