2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30609 | MEDIUM | 4.7 | 0.6% | Apr 25, 2023 | matrix-react-sdk is a react-based SDK for inserting a Matrix chat/VoIP client into a web page. Prior to version 3.71.0, ... |
| CVE-2023-2293 | MEDIUM | 4.8 | 0.6% | Apr 25, 2023 | A vulnerability was found in SourceCodester Purchase Order Management System 1.0. It has been classified as problematic.... |
| CVE-2023-2269 | MEDIUM | 4.4 | 0.2% | Apr 25, 2023 | A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_cl... |
| CVE-2023-24512 | MEDIUM | 6.5 | 0.6% | Apr 25, 2023 | On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a... |
| CVE-2023-23839 | MEDIUM | 6.5 | 1.1% | Apr 25, 2023 | The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allow... |
| CVE-2023-28084 | MEDIUM | 5.5 | 0.2% | Apr 25, 2023 | HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens |
| CVE-2023-25461 | MEDIUM | 4.8 | 0.4% | Apr 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in namithjawahar Wp-Insert plugin <= 2.5.0 versions. |
| CVE-2023-24005 | MEDIUM | 4.8 | 0.4% | Apr 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media Inline Tweet Sharer – Twitter Sharing Plu... |
| CVE-2023-23995 | MEDIUM | 4.8 | 0.4% | Apr 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tim Reeves & David Stöckl TinyMCE Custom Styles plugin... |
| CVE-2023-23889 | MEDIUM | 5.4 | 0.4% | Apr 25, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25... |
| CVE-2023-23866 | MEDIUM | 5.4 | 0.4% | Apr 25, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Carlos Moreira Interactive Geo Maps plugin <= 1.... |
| CVE-2023-23710 | MEDIUM | 4.8 | 0.4% | Apr 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discor... |
| CVE-2023-2282 | MEDIUM | 6.5 | 0.4% | Apr 25, 2023 | Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows... |
| CVE-2023-28090 | MEDIUM | 5.5 | 0.2% | Apr 25, 2023 | An HPE OneView appliance dump may expose SNMPv3 read credentials |
| CVE-2023-28087 | MEDIUM | 5.5 | 0.2% | Apr 25, 2023 | An HPE OneView appliance dump may expose OneView user accounts |
| CVE-2023-28086 | MEDIUM | 5.5 | 0.2% | Apr 25, 2023 | An HPE OneView appliance dump may expose proxy credential settings |
| CVE-2023-25793 | MEDIUM | 4.8 | 0.4% | Apr 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in George Pattihis Link Juice Keeper plugin <= 2.0.2 vers... |
| CVE-2023-25485 | MEDIUM | 4.8 | 0.4% | Apr 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bernhard Kux JSON Content Importer plugin <= 1.3.15 ve... |
| CVE-2023-30545 | MEDIUM | 6.5 | 0.9% | Apr 25, 2023 | PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user ... |
| CVE-2023-30177 | MEDIUM | 6.1 | 0.4% | Apr 25, 2023 | CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name. |
| CVE-2023-29200 | MEDIUM | 6.5 | 0.8% | Apr 25, 2023 | Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can li... |
| CVE-2023-23838 | MEDIUM | 6.5 | 1.3% | Apr 25, 2023 | Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the serv... |
| CVE-2023-25484 | MEDIUM | 4.8 | 0.4% | Apr 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 v... |
| CVE-2023-30402 | MEDIUM | 5.5 | 0.3% | Apr 25, 2023 | YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: Th... |
| CVE-2023-25314 | MEDIUM | 6.1 | 0.4% | Apr 25, 2023 | Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows attackers to gain se... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now