2023 CVE Vulnerabilities
31,400 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5687 | HIGH | 8.8 | 0.3% | Oct 20, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository mosparo/mosparo prior to 1.0.3. |
| CVE-2023-5686 | HIGH | 8.8 | 0.8% | Oct 20, 2023 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. |
| CVE-2023-23373 | HIGH | 8.8 | 1.1% | Oct 20, 2023 | An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow ... |
| CVE-2023-3965 | MEDIUM | 6.1 | 0.4% | Oct 20, 2023 | The nsc theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, a... |
| CVE-2023-3962 | MEDIUM | 6.1 | 0.4% | Oct 20, 2023 | The Winters theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up t... |
| CVE-2023-3933 | MEDIUM | 6.1 | 0.4% | Oct 20, 2023 | The Your Journey theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions... |
| CVE-2023-3487 | HIGH | 7.8 | 0.2% | Oct 20, 2023 | An integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when readi... |
| CVE-2023-46287 | MEDIUM | 6.1 | 0.5% | Oct 20, 2023 | XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php. |
| CVE-2023-5618 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ver... |
| CVE-2023-44483 | MEDIUM | 6.5 | 1.2% | Oct 20, 2023 | All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, a... |
| CVE-2023-44256 | MEDIUM | 6.5 | 1.2% | Oct 20, 2023 | A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2... |
| CVE-2023-34045 | HIGH | 7.8 | 0.2% | Oct 20, 2023 | VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation f... |
| CVE-2023-34046 | HIGH | 7 | 0.1% | Oct 20, 2023 | VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during instal... |
| CVE-2023-34044 | MEDIUM | 6 | 0.2% | Oct 20, 2023 | VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that... |
| CVE-2023-5656 | — | — | — | Oct 20, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5533. Reason: This record is a reservatio... |
| CVE-2023-5615 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-statu... |
| CVE-2023-5602 | HIGH | 8.8 | 0.2% | Oct 20, 2023 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2023-5534 | MEDIUM | 5.4 | 0.2% | Oct 20, 2023 | The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 ... |
| CVE-2023-5533 | CRITICAL | 9.8 | 0.5% | Oct 20, 2023 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks o... |
| CVE-2023-5337 | MEDIUM | 5.4 | 0.3% | Oct 20, 2023 | The Contact form Form For All plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortco... |
| CVE-2023-5292 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acfe_for... |
| CVE-2023-5231 | MEDIUM | 5.4 | 0.3% | Oct 20, 2023 | The Magic Action Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to,... |
| CVE-2023-5121 | MEDIUM | 4.8 | 0.3% | Oct 20, 2023 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set... |
| CVE-2023-5109 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The WP Mailto Links – Protect Email Addresses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wpm... |
| CVE-2023-5086 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Copy Anything to Clipboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'copy' shortcode in... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now