2023 CVE Vulnerabilities
31,400 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-35181 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows us... |
| CVE-2023-35180 | HIGH | 8.8 | 27.4% | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows a... |
| CVE-2023-31046 | MEDIUM | 6.5 | 1.5% | Oct 19, 2023 | A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditi... |
| CVE-2023-45883 | HIGH | 7.8 | 0.2% | Oct 19, 2023 | A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a sta... |
| CVE-2023-45384 | CRITICAL | 9.8 | 0.6% | Oct 19, 2023 | KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the modu... |
| CVE-2023-45379 | CRITICAL | 9.8 | 0.5% | Oct 19, 2023 | In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from PosThemes for PrestaShop, a guest can pe... |
| CVE-2023-43252 | HIGH | 7.8 | 0.5% | Oct 19, 2023 | XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file. |
| CVE-2023-46227 | HIGH | 7.5 | 1.0% | Oct 19, 2023 | Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache... |
| CVE-2023-25753 | MEDIUM | 6.5 | 0.8% | Oct 19, 2023 | There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vu... |
| CVE-2023-34050 | MEDIUM | 4.3 | 1.5% | Oct 19, 2023 | In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class na... |
| CVE-2023-5254 | MEDIUM | 5.3 | 0.8% | Oct 19, 2023 | The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9... |
| CVE-2023-5241 | HIGH | 8.1 | 2.1% | Oct 19, 2023 | The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9... |
| CVE-2023-5212 | HIGH | 8.1 | 1.6% | Oct 19, 2023 | The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as ... |
| CVE-2023-5204 | HIGH | 7.5 | 6.9% | Oct 19, 2023 | The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and includin... |
| CVE-2023-46229 | HIGH | 8.8 | 44.7% | Oct 19, 2023 | LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an e... |
| CVE-2023-46228 | HIGH | 7.8 | 0.3% | Oct 19, 2023 | zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, ... |
| CVE-2023-37503 | CRITICAL | 9.8 | 0.5% | Oct 19, 2023 | HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access... |
| CVE-2023-5639 | MEDIUM | 5.4 | 0.4% | Oct 19, 2023 | The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tmfshortcode' shor... |
| CVE-2023-5638 | MEDIUM | 5.4 | 0.5% | Oct 19, 2023 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcj_image' shortcode ... |
| CVE-2023-5336 | MEDIUM | 6.5 | 0.6% | Oct 19, 2023 | The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's ... |
| CVE-2023-4645 | MEDIUM | 5.3 | 0.6% | Oct 19, 2023 | The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 v... |
| CVE-2023-37504 | MEDIUM | 6.5 | 0.3% | Oct 19, 2023 | HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions ... |
| CVE-2023-36857 | MEDIUM | 6.5 | 0.3% | Oct 19, 2023 | Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a replay vulnerability which could allo... |
| CVE-2023-34441 | HIGH | 8.2 | 0.2% | Oct 19, 2023 | Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a cleartext transmission vulnerability ... |
| CVE-2023-34437 | HIGH | 7.5 | 0.5% | Oct 19, 2023 | Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieva... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now