2023 CVE Vulnerabilities
31,400 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-46298 | HIGH | 7.5 | 1.3% | Oct 22, 2023 | Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached ... |
| CVE-2023-38735 | MEDIUM | 6.5 | 0.5% | Oct 22, 2023 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused ... |
| CVE-2023-38276 | HIGH | 7.5 | 0.4% | Oct 22, 2023 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid... |
| CVE-2023-38275 | HIGH | 7.5 | 0.4% | Oct 22, 2023 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to ... |
| CVE-2023-46078 | HIGH | 8.8 | 0.2% | Oct 21, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in PluginEver WC Serial Numbers plugin <= 1.6.3 versions. |
| CVE-2023-46067 | HIGH | 8.8 | 0.2% | Oct 21, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Qwerty23 Rocket Font plugin <= 1.2.3 versions. |
| CVE-2023-5205 | MEDIUM | 5.4 | 0.3% | Oct 21, 2023 | The Add Custom Body Class plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_custom_body_cla... |
| CVE-2023-4939 | MEDIUM | 5.3 | 0.5% | Oct 21, 2023 | The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due... |
| CVE-2023-4635 | MEDIUM | 6.1 | 0.6% | Oct 21, 2023 | The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up ... |
| CVE-2023-5684 | CRITICAL | 9.8 | 78.4% | Oct 21, 2023 | A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012. It has been declared as critical. Aff... |
| CVE-2023-46055 | HIGH | 8.8 | 1.2% | Oct 21, 2023 | An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a cra... |
| CVE-2023-46054 | MEDIUM | 5.4 | 0.4% | Oct 21, 2023 | Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges ... |
| CVE-2023-5683 | CRITICAL | 9.8 | 18.0% | Oct 21, 2023 | A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231010 and classified as critical. This issue... |
| CVE-2023-5132 | HIGH | 7.5 | 0.6% | Oct 21, 2023 | The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit... |
| CVE-2023-46003 | MEDIUM | 5.4 | 0.5% | Oct 21, 2023 | I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php. |
| CVE-2023-38194 | MEDIUM | 6.1 | 1.1% | Oct 21, 2023 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter. |
| CVE-2023-38193 | HIGH | 8.8 | 1.3% | Oct 21, 2023 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command l... |
| CVE-2023-38192 | MEDIUM | 6.1 | 1.1% | Oct 21, 2023 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwor... |
| CVE-2023-38190 | HIGH | 8.8 | 0.7% | Oct 21, 2023 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter. |
| CVE-2023-45682 | HIGH | 7.1 | 0.6% | Oct 21, 2023 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of boun... |
| CVE-2023-45681 | HIGH | 7.8 | 0.5% | Oct 21, 2023 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory writ... |
| CVE-2023-45680 | MEDIUM | 5.5 | 0.5% | Oct 21, 2023 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allo... |
| CVE-2023-45679 | HIGH | 7.8 | 0.5% | Oct 21, 2023 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allo... |
| CVE-2023-45678 | HIGH | 7.8 | 0.7% | Oct 21, 2023 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of buff... |
| CVE-2023-45677 | HIGH | 7.8 | 0.5% | Oct 21, 2023 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of boun... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now