2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5082 | HIGH | 7.2 | 0.7% | Nov 6, 2023 | The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using ... |
| CVE-2023-4930 | MEDIUM | 6.5 | 0.4% | Nov 6, 2023 | The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores a... |
| CVE-2023-4858 | MEDIUM | 4.8 | 0.4% | Nov 6, 2023 | The Simple Table Manager WordPress plugin through 1.5.6 does not sanitise and escape some of its settings, which could a... |
| CVE-2023-4810 | MEDIUM | 4.8 | 0.4% | Nov 6, 2023 | The Responsive Pricing Table WordPress plugin before 5.1.8 does not sanitise and escape some of its settings, which coul... |
| CVE-2023-5777 | CRITICAL | 9.8 | 0.5% | Nov 6, 2023 | Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the cra... |
| CVE-2023-5719 | CRITICAL | 9.8 | 0.5% | Nov 6, 2023 | The Crimson 3.2 Windows-based configuration tool allows users with administrative access to define new passwords for us... |
| CVE-2023-46732 | MEDIUM | 6.1 | 2.2% | Nov 6, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulner... |
| CVE-2023-46731 | CRITICAL | 9.8 | 88.5% | Nov 6, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't p... |
| CVE-2023-46254 | MEDIUM | 4.3 | 0.4% | Nov 6, 2023 | capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used... |
| CVE-2023-39345 | HIGH | 7.5 | 0.5% | Nov 6, 2023 | strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked... |
| CVE-2023-4700 | MEDIUM | 6.5 | 0.4% | Nov 6, 2023 | An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 1... |
| CVE-2023-46728 | HIGH | 7.5 | 6.0% | Nov 6, 2023 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid ... |
| CVE-2023-46251 | MEDIUM | 6.1 | 0.5% | Nov 6, 2023 | MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape... |
| CVE-2023-45827 | CRITICAL | 9.8 | 1.2% | Nov 6, 2023 | Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions t... |
| CVE-2023-44398 | HIGH | 8.8 | 1.0% | Nov 6, 2023 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada... |
| CVE-2023-4535 | LOW | 3.8 | 0.5% | Nov 6, 2023 | An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key enc... |
| CVE-2023-40661 | MEDIUM | 6.4 | 1.2% | Nov 6, 2023 | Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process u... |
| CVE-2023-40660 | MEDIUM | 6.6 | 0.9% | Nov 6, 2023 | A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process... |
| CVE-2023-5969 | MEDIUM | 5.3 | 0.5% | Nov 6, 2023 | Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially... |
| CVE-2023-5968 | MEDIUM | 4.9 | 0.5% | Nov 6, 2023 | Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being i... |
| CVE-2023-5967 | MEDIUM | 4.3 | 0.5% | Nov 6, 2023 | Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a Use... |
| CVE-2023-5678 | MEDIUM | 5.3 | 4.5% | Nov 6, 2023 | Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be... |
| CVE-2023-41378 | HIGH | 7.5 | 0.7% | Nov 6, 2023 | In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.1... |
| CVE-2023-5950 | MEDIUM | 6.1 | 0.5% | Nov 6, 2023 | Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerabi... |
| CVE-2023-5964 | HIGH | 7.2 | 0.8% | Nov 6, 2023 | The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exch... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now