2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5819 | MEDIUM | 4.8 | 0.5% | Nov 7, 2023 | The Amazonify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to... |
| CVE-2023-5818 | MEDIUM | 4.3 | 0.2% | Nov 7, 2023 | The Amazonify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8... |
| CVE-2023-4956 | MEDIUM | 4.3 | 0.5% | Nov 7, 2023 | A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user in... |
| CVE-2023-4154 | MEDIUM | 6.5 | 1.2% | Nov 7, 2023 | A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directo... |
| CVE-2023-46243 | HIGH | 8.8 | 1.0% | Nov 7, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver... |
| CVE-2023-37835 | — | — | — | Nov 7, 2023 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-45396. Reason: This record is a duplicate of CVE-2023-... |
| CVE-2023-5998 | HIGH | 7.5 | 0.6% | Nov 7, 2023 | Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV. |
| CVE-2023-5309 | CRITICAL | 9.8 | 0.5% | Nov 7, 2023 | Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for... |
| CVE-2023-46253 | HIGH | 7.2 | 1.5% | Nov 7, 2023 | Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file wr... |
| CVE-2023-46252 | MEDIUM | 6.1 | 0.5% | Nov 7, 2023 | Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in ... |
| CVE-2023-46244 | HIGH | 8.8 | 0.8% | Nov 7, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver... |
| CVE-2023-46242 | HIGH | 8.8 | 0.4% | Nov 7, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver... |
| CVE-2023-46744 | MEDIUM | 5.4 | 0.5% | Nov 7, 2023 | Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (X... |
| CVE-2023-46737 | MEDIUM | 5.3 | 0.6% | Nov 7, 2023 | Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker contro... |
| CVE-2023-46730 | HIGH | 8.8 | 0.6% | Nov 7, 2023 | Group-Office is an enterprise CRM and groupware tool. In affected versions there is full Server-Side Request Forgery (SS... |
| CVE-2023-46501 | CRITICAL | 9.1 | 1.3% | Nov 7, 2023 | An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view a... |
| CVE-2023-41798 | HIGH | 8.8 | 0.5% | Nov 7, 2023 | Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Direct... |
| CVE-2023-32966 | MEDIUM | 6.1 | 0.2% | Nov 7, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab Jazz Popups leads to Stored XSS.This issue affects Jazz Popup... |
| CVE-2023-28499 | MEDIUM | 5.4 | 0.5% | Nov 7, 2023 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML... |
| CVE-2023-0898 | HIGH | 7.3 | 0.3% | Nov 7, 2023 | General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in... |
| CVE-2023-5179 | HIGH | 7.8 | 0.3% | Nov 7, 2023 | An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat ... |
| CVE-2023-4295 | HIGH | 7.8 | 0.3% | Nov 7, 2023 | A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. |
| CVE-2023-4272 | MEDIUM | 5.5 | 0.3% | Nov 7, 2023 | A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory. ... |
| CVE-2023-47360 | HIGH | 7.5 | 0.9% | Nov 7, 2023 | Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length. |
| CVE-2023-47359 | CRITICAL | 9.8 | 1.1% | Nov 7, 2023 | Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in fun... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now