2023 CVE Vulnerabilities
31,399 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46090 | MEDIUM | 6.1 | 0.3% | Oct 26, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions. |
| CVE-2023-41096 | MEDIUM | 6.1 | 0.1% | Oct 26, 2023 | Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High module... |
| CVE-2023-41095 | CRITICAL | 9.1 | 0.2% | Oct 26, 2023 | Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High module... |
| CVE-2023-5781 | CRITICAL | 9.8 | 0.7% | Oct 26, 2023 | A vulnerability, which was classified as critical, has been found in Tongda OA 2017 11.10. This issue affects the functi... |
| CVE-2023-5780 | CRITICAL | 9.8 | 0.7% | Oct 26, 2023 | A vulnerability classified as critical was found in Tongda OA 2017 11.10. This vulnerability affects unknown code of the... |
| CVE-2023-46094 | MEDIUM | 6.1 | 0.3% | Oct 26, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track Google Analytics 4, Facebook Pixel & Conv... |
| CVE-2023-46088 | MEDIUM | 4.8 | 0.3% | Oct 26, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology WP Full Stripe Free plugin <= 1.6.1 versi... |
| CVE-2023-46081 | MEDIUM | 6.1 | 0.3% | Oct 26, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions. |
| CVE-2023-46077 | MEDIUM | 6.1 | 0.3% | Oct 26, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plugin <= 2.2... |
| CVE-2023-46076 | MEDIUM | 6.1 | 0.3% | Oct 26, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao WooCommerce PDF Invoice Builder, Create invoices, p... |
| CVE-2023-46075 | MEDIUM | 6.1 | 0.3% | Oct 26, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Contact Form Builder, Contact Widget plugin <= 2.... |
| CVE-2023-32116 | MEDIUM | 4.8 | 0.3% | Oct 26, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in TotalPress.Org Custom post types, Custom Fields & more... |
| CVE-2023-5802 | HIGH | 8.8 | 0.2% | Oct 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Mihai Iova WordPress Knowledge base & Documentation Plugin – WP Knowl... |
| CVE-2023-46074 | MEDIUM | 6.1 | 0.3% | Oct 26, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Borbis Media FreshMail For WordPress plugin <= 2.3.2 versi... |
| CVE-2023-46072 | MEDIUM | 6.1 | 0.3% | Oct 26, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin ... |
| CVE-2023-30492 | MEDIUM | 5.4 | 0.3% | Oct 26, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vark Minimum Purchase for WooCommerce plugin <= ... |
| CVE-2023-5798 | HIGH | 8.8 | 0.7% | Oct 26, 2023 | The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_ge... |
| CVE-2023-5139 | HIGH | 7.8 | 0.4% | Oct 26, 2023 | Potential buffer overflow vulnerability at the following location in the Zephyr STM32 Crypto driver |
| CVE-2023-46754 | MEDIUM | 5.3 | 0.4% | Oct 26, 2023 | The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary num... |
| CVE-2023-46753 | MEDIUM | 5.9 | 0.8% | Oct 26, 2023 | An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without manda... |
| CVE-2023-46752 | MEDIUM | 5.9 | 0.8% | Oct 26, 2023 | An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash. |
| CVE-2023-31421 | HIGH | 7.5 | 0.3% | Oct 26, 2023 | It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whe... |
| CVE-2023-31422 | HIGH | 7.5 | 0.7% | Oct 26, 2023 | An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. Th... |
| CVE-2023-46667 | HIGH | 8.1 | 0.5% | Oct 26, 2023 | An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into th... |
| CVE-2023-46668 | CRITICAL | 9.1 | 0.3% | Oct 26, 2023 | If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitl... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now