2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5381 | MEDIUM | 4.8 | 0.5% | Nov 15, 2023 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ver... |
| CVE-2023-4723 | MEDIUM | 5.3 | 0.9% | Nov 15, 2023 | The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and... |
| CVE-2023-4690 | MEDIUM | 4.3 | 0.3% | Nov 15, 2023 | The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc... |
| CVE-2023-4689 | MEDIUM | 4.3 | 0.3% | Nov 15, 2023 | The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc... |
| CVE-2023-48200 | MEDIUM | 5.4 | 0.8% | Nov 15, 2023 | Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensiti... |
| CVE-2023-48199 | HIGH | 7.8 | 0.5% | Nov 15, 2023 | HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTM... |
| CVE-2023-48198 | MEDIUM | 5.4 | 0.7% | Nov 15, 2023 | A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy ... |
| CVE-2023-48197 | MEDIUM | 5.4 | 0.7% | Nov 15, 2023 | Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to... |
| CVE-2023-48365 | CRITICAL | 9.9 | 24.7% | Nov 15, 2023 | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.... |
| CVE-2023-47444 | HIGH | 8.8 | 1.8% | Nov 15, 2023 | An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privi... |
| CVE-2023-47347 | HIGH | 7.5 | 0.7% | Nov 15, 2023 | Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages w... |
| CVE-2023-47345 | HIGH | 7.5 | 0.9% | Nov 15, 2023 | Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message wi... |
| CVE-2023-41442 | CRITICAL | 9.8 | 1.3% | Nov 15, 2023 | An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute... |
| CVE-2023-6105 | MEDIUM | 5.5 | 0.7% | Nov 15, 2023 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys bein... |
| CVE-2023-48224 | CRITICAL | 9.1 | 1.0% | Nov 15, 2023 | Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime ... |
| CVE-2023-47638 | — | — | — | Nov 15, 2023 | Rejected reason: Confirm reference is not public. |
| CVE-2023-47637 | HIGH | 8.8 | 1.2% | Nov 15, 2023 | Pimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` end... |
| CVE-2023-47636 | MEDIUM | 5.3 | 0.7% | Nov 15, 2023 | The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable th... |
| CVE-2023-41699 | MEDIUM | 6.1 | 0.4% | Nov 15, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (... |
| CVE-2023-30954 | LOW | 3.7 | 0.3% | Nov 15, 2023 | The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls ne... |
| CVE-2023-22818 | HIGH | 7.8 | 0.2% | Nov 15, 2023 | Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could... |
| CVE-2023-48219 | MEDIUM | 6.1 | 0.7% | Nov 15, 2023 | TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyM... |
| CVE-2023-48014 | HIGH | 7.8 | 0.4% | Nov 15, 2023 | GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a stack overflow via the hevc_parse_vps_extension funct... |
| CVE-2023-48013 | HIGH | 7.8 | 0.3% | Nov 15, 2023 | GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at /... |
| CVE-2023-48011 | HIGH | 7.8 | 0.3% | Nov 15, 2023 | GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a heap-use-after-free via the flush_ref_samples functio... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now