2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47379 | MEDIUM | 5.4 | 0.5% | Nov 8, 2023 | Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload func... |
| CVE-2023-46643 | MEDIUM | 6.1 | 0.4% | Nov 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GARY JEZORSKI CloudNet360 plugin <= 3.2.0 versions. |
| CVE-2023-46642 | MEDIUM | 4.8 | 0.4% | Nov 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in sahumedia SAHU TikTok Pixel for E-Commerce plugin <= 1... |
| CVE-2023-5759 | HIGH | 7.5 | 0.9% | Nov 8, 2023 | In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified.... |
| CVE-2023-5136 | MEDIUM | 5.5 | 0.3% | Nov 8, 2023 | An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An atta... |
| CVE-2023-47397 | CRITICAL | 9.8 | 1.0% | Nov 8, 2023 | WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php. |
| CVE-2023-47107 | HIGH | 8.8 | 0.6% | Nov 8, 2023 | PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component ... |
| CVE-2023-46640 | MEDIUM | 5.4 | 0.4% | Nov 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in D. Relton Medialist plugin <= 1.3.9 versions. |
| CVE-2023-46627 | MEDIUM | 6.1 | 0.4% | Nov 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 v... |
| CVE-2023-46626 | MEDIUM | 6.1 | 0.4% | Nov 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FLOWFACT WP Connector plugin <= 2.1.7 versions. |
| CVE-2023-46621 | MEDIUM | 6.1 | 0.4% | Nov 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin... |
| CVE-2023-46613 | MEDIUM | 5.4 | 0.4% | Nov 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jens Kuerschner Add to Calendar Button plugin <=... |
| CVE-2023-45849 | CRITICAL | 9.8 | 1.1% | Nov 8, 2023 | An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2.... |
| CVE-2023-45319 | HIGH | 7.5 | 0.9% | Nov 8, 2023 | In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was id... |
| CVE-2023-45140 | MEDIUM | 4.6 | 0.4% | Nov 8, 2023 | The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. SCP and SFTP plugins... |
| CVE-2023-35767 | HIGH | 7.5 | 0.9% | Nov 8, 2023 | In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was ... |
| CVE-2023-32298 | MEDIUM | 6.1 | 0.4% | Nov 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kathy Darling Simple User Listing plugin <= 1.9.2 versions... |
| CVE-2023-6012 | CRITICAL | 9.8 | 0.9% | Nov 8, 2023 | An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vu... |
| CVE-2023-46759 | HIGH | 7.5 | 0.4% | Nov 8, 2023 | Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service co... |
| CVE-2023-46758 | HIGH | 7.5 | 0.5% | Nov 8, 2023 | Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerabilit... |
| CVE-2023-46757 | HIGH | 7.5 | 0.4% | Nov 8, 2023 | The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of... |
| CVE-2023-46756 | MEDIUM | 5.3 | 0.3% | Nov 8, 2023 | Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may caus... |
| CVE-2023-46774 | HIGH | 7.5 | 0.5% | Nov 8, 2023 | Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC ava... |
| CVE-2023-46772 | HIGH | 7.5 | 0.5% | Nov 8, 2023 | Vulnerability of parameters being out of the value range in the QMI service module. Successful exploitation of this vuln... |
| CVE-2023-46767 | HIGH | 7.5 | 0.5% | Nov 8, 2023 | Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause p... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now