2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23369 | CRITICAL | 9.8 | 14.4% | Nov 3, 2023 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2023-23368 | CRITICAL | 9.8 | 18.7% | Nov 3, 2023 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2023-46980 | CRITICAL | 9.8 | 1.5% | Nov 3, 2023 | An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privile... |
| CVE-2023-46404 | CRITICAL | 9.9 | 1.9% | Nov 3, 2023 | PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping ... |
| CVE-2023-5946 | MEDIUM | 6.1 | 0.4% | Nov 3, 2023 | The Digirisk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_group_id' parameter i... |
| CVE-2023-5088 | HIGH | 7 | 0.2% | Nov 3, 2023 | A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset... |
| CVE-2023-5945 | MEDIUM | 5.4 | 0.3% | Nov 3, 2023 | The video carousel slider with lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0.... |
| CVE-2023-5707 | MEDIUM | 5.4 | 0.5% | Nov 3, 2023 | The SEO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slider' shortcode and... |
| CVE-2023-46947 | HIGH | 8.8 | 1.3% | Nov 3, 2023 | Subrion 4.2.1 has a remote command execution vulnerability in the backend. |
| CVE-2023-3961 | CRITICAL | 9.8 | 2.4% | Nov 3, 2023 | A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain socke... |
| CVE-2023-26015 | CRITICAL | 9.8 | 0.7% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson M... |
| CVE-2023-25960 | CRITICAL | 9.8 | 0.7% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – ... |
| CVE-2023-4592 | MEDIUM | 6.1 | 0.4% | Nov 3, 2023 | A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability... |
| CVE-2023-4591 | CRITICAL | 9.8 | 0.6% | Nov 3, 2023 | A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an ... |
| CVE-2023-41652 | CRITICAL | 9.8 | 0.9% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP... |
| CVE-2023-3277 | CRITICAL | 9.8 | 2.9% | Nov 3, 2023 | The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up... |
| CVE-2023-34383 | CRITICAL | 9.8 | 0.6% | Nov 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project ... |
| CVE-2023-4769 | HIGH | 8.8 | 3.3% | Nov 3, 2023 | A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfi... |
| CVE-2023-4768 | MEDIUM | 6.1 | 2.9% | Nov 3, 2023 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerabilit... |
| CVE-2023-4767 | MEDIUM | 6.1 | 2.9% | Nov 3, 2023 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerabilit... |
| CVE-2023-4043 | HIGH | 7.5 | 0.8% | Nov 3, 2023 | In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exp... |
| CVE-2023-1476 | HIGH | 7 | 0.2% | Nov 3, 2023 | A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue ... |
| CVE-2023-5824 | HIGH | 7.5 | 5.2% | Nov 3, 2023 | A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. Howeve... |
| CVE-2023-4091 | MEDIUM | 6.5 | 1.2% | Nov 3, 2023 | A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permis... |
| CVE-2023-46848 | HIGH | 7.5 | 10.2% | Nov 3, 2023 | Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Reques... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now