2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5652 | CRITICAL | 9.8 | 63.7% | Nov 20, 2023 | The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not esca... |
| CVE-2023-5640 | CRITICAL | 9.8 | 1.0% | Nov 20, 2023 | The Article Analytics WordPress plugin does not properly sanitise and escape a parameter before using it in a SQL statem... |
| CVE-2023-5340 | CRITICAL | 9.8 | 1.2% | Nov 20, 2023 | The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX actio... |
| CVE-2023-38880 | CRITICAL | 9.8 | 1.0% | Nov 20, 2023 | The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database b... |
| CVE-2023-35762 | CRITICAL | 9.8 | 1.7% | Nov 20, 2023 | Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could... |
| CVE-2023-29155 | CRITICAL | 9.8 | 0.9% | Nov 20, 2023 | Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system ... |
| CVE-2023-46302 | CRITICAL | 9.8 | 1.7% | Nov 20, 2023 | Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml htt... |
| CVE-2023-46700 | CRITICAL | 9.8 | 1.0% | Nov 20, 2023 | SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.... |
| CVE-2023-4214 | CRITICAL | 9.8 | 0.9% | Nov 18, 2023 | The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5... |
| CVE-2023-48028 | CRITICAL | 9.8 | 1.1% | Nov 18, 2023 | kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an at... |
| CVE-2023-43177 | CRITICAL | 9.8 | 81.8% | Nov 18, 2023 | CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes... |
| CVE-2023-6188 | CRITICAL | 9.8 | 1.0% | Nov 17, 2023 | A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown ... |
| CVE-2023-44353 | CRITICAL | 9.8 | 80.2% | Nov 17, 2023 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted... |
| CVE-2023-44351 | CRITICAL | 9.8 | 50.2% | Nov 17, 2023 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted... |
| CVE-2023-44350 | CRITICAL | 9.8 | 64.6% | Nov 17, 2023 | Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted... |
| CVE-2023-44324 | CRITICAL | 9.8 | 1.4% | Nov 17, 2023 | Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability th... |
| CVE-2023-41101 | CRITICAL | 9.8 | 1.9% | Nov 17, 2023 | An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not ... |
| CVE-2023-38316 | CRITICAL | 9.8 | 1.1% | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, a... |
| CVE-2023-48659 | CRITICAL | 9.8 | 0.9% | Nov 17, 2023 | An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing. |
| CVE-2023-48658 | CRITICAL | 9.8 | 0.9% | Nov 17, 2023 | An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, un... |
| CVE-2023-48657 | CRITICAL | 9.8 | 0.9% | Nov 17, 2023 | An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters. |
| CVE-2023-48656 | CRITICAL | 9.8 | 0.9% | Nov 17, 2023 | An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses. |
| CVE-2023-48655 | CRITICAL | 9.8 | 0.9% | Nov 17, 2023 | An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filt... |
| CVE-2023-48648 | CRITICAL | 9.8 | 1.2% | Nov 17, 2023 | Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insec... |
| CVE-2023-48031 | CRITICAL | 9.8 | 1.4% | Nov 17, 2023 | OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attac... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now