2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47532 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themeum WP Crowdfunding plugin <= 2.1.6 versions. |
| CVE-2023-47528 | MEDIUM | 4.8 | 0.4% | Nov 14, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sajjad Hossain Sagor WP Edit Username plugin <= 1.0.5 ... |
| CVE-2023-47524 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability (requires PHP 8.x) in CodeBard CodeBard's Patron Button and W... |
| CVE-2023-47522 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Feed plugin <= 2.2.1 versions. |
| CVE-2023-47520 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Uno (miunosoft) Responsive Column Widgets plugin <... |
| CVE-2023-46582 | HIGH | 7.8 | 0.3% | Nov 14, 2023 | SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary SQL commands via ... |
| CVE-2023-46581 | MEDIUM | 5.5 | 0.3% | Nov 14, 2023 | SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name... |
| CVE-2023-46580 | MEDIUM | 5.4 | 0.5% | Nov 14, 2023 | Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the... |
| CVE-2023-46026 | MEDIUM | 4.8 | 0.4% | Nov 14, 2023 | Cross Site Scripting (XSS) vulnerability in profile.php in phpgurukul Teacher Subject Allocation Management System 1.0 a... |
| CVE-2023-46025 | MEDIUM | 4.9 | 0.7% | Nov 14, 2023 | SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows at... |
| CVE-2023-46024 | HIGH | 7.5 | 1.1% | Nov 14, 2023 | SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers... |
| CVE-2023-46023 | MEDIUM | 6.5 | 0.6% | Nov 14, 2023 | SQL injection vulnerability in addTask.php in Code-Projects Simple Task List 1.0 allows attackers to obtain sensitive in... |
| CVE-2023-46022 | HIGH | 7.8 | 0.8% | Nov 14, 2023 | SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands... |
| CVE-2023-39537 | HIGH | 7.8 | 0.2% | Nov 14, 2023 | AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network... |
| CVE-2023-39536 | HIGH | 7.8 | 0.2% | Nov 14, 2023 | AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network... |
| CVE-2023-39535 | HIGH | 7.8 | 0.2% | Nov 14, 2023 | AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network... |
| CVE-2023-36558 | MEDIUM | 5.5 | 1.1% | Nov 14, 2023 | ASP.NET Core Security Feature Bypass Vulnerability |
| CVE-2023-36038 | HIGH | 7.5 | 2.8% | Nov 14, 2023 | ASP.NET Core Denial of Service Vulnerability |
| CVE-2023-5528 | HIGH | 8.8 | 3.6% | Nov 14, 2023 | A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes ... |
| CVE-2023-47641 | MEDIUM | 6.5 | 0.8% | Nov 14, 2023 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a secu... |
| CVE-2023-47640 | HIGH | 8.8 | 0.4% | Nov 14, 2023 | DataHub is an open-source metadata platform. The HMAC signature for DataHub Frontend sessions was being signed using a S... |
| CVE-2023-47631 | HIGH | 8.8 | 0.4% | Nov 14, 2023 | vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party... |
| CVE-2023-47630 | HIGH | 7.1 | 0.3% | Nov 14, 2023 | Kyverno is a policy engine designed for Kubernetes. An issue was found in Kyverno that allowed an attacker to control th... |
| CVE-2023-47627 | HIGH | 7.5 | 0.9% | Nov 14, 2023 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous ... |
| CVE-2023-47549 | MEDIUM | 6.1 | 0.4% | Nov 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now