2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5252 | MEDIUM | 5.4 | 0.4% | Oct 30, 2023 | The FareHarbor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and i... |
| CVE-2023-5251 | MEDIUM | 5.4 | 0.5% | Oct 30, 2023 | The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing ... |
| CVE-2023-5250 | HIGH | 8.8 | 1.1% | Oct 30, 2023 | The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a s... |
| CVE-2023-5199 | HIGH | 8.8 | 1.4% | Oct 30, 2023 | The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and ... |
| CVE-2023-5164 | MEDIUM | 5.4 | 0.4% | Oct 30, 2023 | The Bellows Accordion Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions ... |
| CVE-2023-5049 | MEDIUM | 5.4 | 0.5% | Oct 30, 2023 | The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'raf... |
| CVE-2023-44078 | — | — | — | Oct 30, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-41605 | — | — | — | Oct 30, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-40943 | — | — | — | Oct 30, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-5833 | HIGH | 8.8 | 0.6% | Oct 30, 2023 | Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0. |
| CVE-2023-5832 | CRITICAL | 9.1 | 0.7% | Oct 30, 2023 | Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0. |
| CVE-2023-5844 | HIGH | 7.2 | 0.6% | Oct 30, 2023 | Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0. |
| CVE-2023-42431 | MEDIUM | 5.4 | 0.3% | Oct 30, 2023 | Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbi... |
| CVE-2023-45799 | CRITICAL | 9.8 | 0.3% | Oct 30, 2023 | In MLSoft TCO!stream versions 8.0.22.1115 and below, a vulnerability exists due to insufficient permission validation. T... |
| CVE-2023-45798 | CRITICAL | 9.8 | 0.6% | Oct 30, 2023 | In Yettiesoft VestCert versions 2.36 to 2.5.29, a vulnerability exists due to improper validation of third-party modules... |
| CVE-2023-45797 | CRITICAL | 9.8 | 0.8% | Oct 30, 2023 | A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotel... |
| CVE-2023-45746 | MEDIUM | 5.4 | 0.4% | Oct 30, 2023 | Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary ... |
| CVE-2023-44141 | HIGH | 7.8 | 0.3% | Oct 30, 2023 | Inkdrop prior to v5.6.0 allows a local attacker to conduct a code injection attack by having a legitimate user open a sp... |
| CVE-2023-46867 | MEDIUM | 6.5 | 0.5% | Oct 30, 2023 | In International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a... |
| CVE-2023-46866 | MEDIUM | 6.5 | 0.6% | Oct 30, 2023 | In International Color Consortium DemoIccMAX 79ecb74, CIccCLUT::Interp3d in IccProfLib/IccTagLut.cpp in libSampleICC.a a... |
| CVE-2023-5842 | MEDIUM | 4.8 | 0.5% | Oct 30, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5. |
| CVE-2023-46865 | HIGH | 7.2 | 20.3% | Oct 30, 2023 | /api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PH... |
| CVE-2023-4393 | MEDIUM | 6.1 | 0.3% | Oct 30, 2023 | HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform... |
| CVE-2023-46864 | MEDIUM | 5.3 | 0.7% | Oct 30, 2023 | Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/d... |
| CVE-2023-46863 | HIGH | 7.5 | 0.9% | Oct 30, 2023 | Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/downl... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now