2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5976 | MEDIUM | 4.3 | 0.4% | Nov 7, 2023 | Improper Access Control in GitHub repository microweber/microweber prior to 2.0. |
| CVE-2023-5904 | MEDIUM | 5.4 | 0.4% | Nov 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5903 | MEDIUM | 5.4 | 0.4% | Nov 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5902 | MEDIUM | 4.3 | 0.3% | Nov 7, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5901 | MEDIUM | 4.8 | 0.5% | Nov 7, 2023 | Cross-site Scripting in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5900 | MEDIUM | 4.3 | 0.2% | Nov 7, 2023 | Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-5748 | MEDIUM | 5.5 | 0.2% | Nov 7, 2023 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VP... |
| CVE-2023-41036 | HIGH | 7.8 | 0.3% | Nov 7, 2023 | Macvim is a text editor for MacOS. Prior to version 178, Macvim makes use of an insecure interprocess communication (IPC... |
| CVE-2023-40453 | MEDIUM | 6.5 | 0.9% | Nov 7, 2023 | Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, whi... |
| CVE-2023-38509 | MEDIUM | 4.3 | 0.7% | Nov 7, 2023 | XWiki Platform is a generic wiki platform. In org.xwiki.platform:xwiki-platform-livetable-ui starting with version 3.5-m... |
| CVE-2023-2675 | CRITICAL | 9.8 | 0.6% | Nov 7, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223. |
| CVE-2023-36409 | MEDIUM | 6.5 | 0.9% | Nov 7, 2023 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2023-36769 | MEDIUM | 5.4 | 0.4% | Nov 6, 2023 | Microsoft OneNote Spoofing Vulnerability |
| CVE-2023-47004 | HIGH | 8.8 | 1.0% | Nov 6, 2023 | Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to exe... |
| CVE-2023-45556 | MEDIUM | 5.4 | 0.5% | Nov 6, 2023 | Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via th... |
| CVE-2023-5771 | MEDIUM | 6.1 | 0.3% | Nov 6, 2023 | Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can sen... |
| CVE-2023-5605 | MEDIUM | 4.8 | 0.4% | Nov 6, 2023 | The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2023-5601 | CRITICAL | 9.8 | 0.9% | Nov 6, 2023 | The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, all... |
| CVE-2023-5530 | MEDIUM | 4.8 | 0.6% | Nov 6, 2023 | The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could a... |
| CVE-2023-5454 | HIGH | 7.5 | 0.6% | Nov 6, 2023 | The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, all... |
| CVE-2023-5355 | HIGH | 8.1 | 0.7% | Nov 6, 2023 | The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files,... |
| CVE-2023-5354 | MEDIUM | 6.1 | 0.4% | Nov 6, 2023 | The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2023-5352 | MEDIUM | 4.3 | 0.4% | Nov 6, 2023 | The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing us... |
| CVE-2023-5228 | MEDIUM | 4.8 | 0.6% | Nov 6, 2023 | The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could all... |
| CVE-2023-5181 | MEDIUM | 4.8 | 0.4% | Nov 6, 2023 | The WP Discord Invite WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now