2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5821 | MEDIUM | 6.5 | 0.3% | Oct 27, 2023 | The Thumbnail carousel slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is d... |
| CVE-2023-5820 | HIGH | 8.8 | 0.3% | Oct 27, 2023 | The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This... |
| CVE-2023-5705 | MEDIUM | 5.4 | 0.4% | Oct 27, 2023 | The VK Filter Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk_filter_searc... |
| CVE-2023-5570 | HIGH | 7.5 | 0.4% | Oct 27, 2023 | Improper Protection for Outbound Error Messages and Alert Signals vulnerability in Inohom Home Manager Gateway allows Ac... |
| CVE-2023-5817 | MEDIUM | 5.4 | 0.5% | Oct 27, 2023 | The Neon text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's neontext_box shortcode ... |
| CVE-2023-5774 | MEDIUM | 5.4 | 0.5% | Oct 27, 2023 | The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in... |
| CVE-2023-46199 | MEDIUM | 4.8 | 0.3% | Oct 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Triberr plugin <= 4.1.1 versions. |
| CVE-2023-46194 | MEDIUM | 6.1 | 0.3% | Oct 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <... |
| CVE-2023-46192 | MEDIUM | 4.8 | 0.3% | Oct 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Internet Marketing Ninjas Internal Link Building plugi... |
| CVE-2023-46153 | MEDIUM | 6.1 | 0.4% | Oct 27, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.9 versions. |
| CVE-2023-46093 | MEDIUM | 4.8 | 0.3% | Oct 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in LionScripts.Com Webmaster Tools plugin <= 2.0 versions... |
| CVE-2023-46091 | MEDIUM | 4.8 | 0.3% | Oct 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bala Krishna, Sergey Yakovlev Category SEO Meta Tags p... |
| CVE-2023-44220 | HIGH | 7.3 | 0.3% | Oct 27, 2023 | SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking... |
| CVE-2023-44219 | HIGH | 7.8 | 0.2% | Oct 27, 2023 | A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earli... |
| CVE-2023-34059 | HIGH | 7 | 0.4% | Oct 27, 2023 | open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with no... |
| CVE-2023-34058 | HIGH | 7.5 | 0.7% | Oct 27, 2023 | VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operat... |
| CVE-2023-34057 | HIGH | 7.8 | 0.2% | Oct 27, 2023 | VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest vi... |
| CVE-2023-5051 | MEDIUM | 5.4 | 0.4% | Oct 27, 2023 | The CallRail Phone Call Tracking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callrail_for... |
| CVE-2023-46818 | HIGH | 7.2 | 13.9% | Oct 27, 2023 | An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by ... |
| CVE-2023-46816 | HIGH | 8.8 | 0.6% | Oct 27, 2023 | An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulne... |
| CVE-2023-46815 | HIGH | 8.8 | 0.6% | Oct 27, 2023 | An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. An Unrestricted File Upload vulnerability has... |
| CVE-2023-46504 | MEDIUM | 5.4 | 0.4% | Oct 27, 2023 | Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a physically proximate attacker to execute a... |
| CVE-2023-46503 | MEDIUM | 6.1 | 0.5% | Oct 27, 2023 | Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a remote attacker to execute arbitrary code ... |
| CVE-2023-45499 | CRITICAL | 9.8 | 7.9% | Oct 27, 2023 | VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials. |
| CVE-2023-45498 | CRITICAL | 9.8 | 20.5% | Oct 27, 2023 | VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now