2023 CVE Vulnerabilities
31,401 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45905 | HIGH | 8.8 | 0.3% | Oct 17, 2023 | Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add. |
| CVE-2023-45904 | HIGH | 8.8 | 0.3% | Oct 17, 2023 | Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update. |
| CVE-2023-45903 | HIGH | 8.8 | 0.3% | Oct 17, 2023 | Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete. |
| CVE-2023-45902 | HIGH | 8.8 | 0.3% | Oct 17, 2023 | Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/del... |
| CVE-2023-45901 | HIGH | 8.8 | 0.3% | Oct 17, 2023 | Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\/category\/add... |
| CVE-2023-43959 | HIGH | 8.8 | 1.6% | Oct 17, 2023 | An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted ... |
| CVE-2023-20598 | HIGH | 7.8 | 0.5% | Oct 17, 2023 | An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an I... |
| CVE-2023-44824 | HIGH | 7.8 | 0.3% | Oct 17, 2023 | An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploade... |
| CVE-2023-43777 | MEDIUM | 6.5 | 0.3% | Oct 17, 2023 | Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining param... |
| CVE-2023-43776 | MEDIUM | 6.6 | 0.1% | Oct 17, 2023 | Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unautho... |
| CVE-2023-42627 | MEDIUM | 5.4 | 2.3% | Oct 17, 2023 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.... |
| CVE-2023-45007 | MEDIUM | 6.1 | 0.3% | Oct 17, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Fotomoto plugin <= 1.2.8 versions. |
| CVE-2023-45006 | MEDIUM | 6.1 | 0.3% | Oct 17, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ByConsole WooODT Lite – WooCommerce Order Delivery or Pick... |
| CVE-2023-45004 | MEDIUM | 6.1 | 0.3% | Oct 17, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wp3sixty Woo Custom Emails plugin <= 2.2 versions. |
| CVE-2023-42628 | MEDIUM | 5.4 | 2.2% | Oct 17, 2023 | Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay... |
| CVE-2023-39902 | HIGH | 7.8 | 0.1% | Oct 17, 2023 | A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i... |
| CVE-2023-45010 | MEDIUM | 4.8 | 0.3% | Oct 17, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex MacArthur Complete Open Graph plugin <= 3.4.5 ver... |
| CVE-2023-45003 | MEDIUM | 6.1 | 0.3% | Oct 17, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins Social Feed | Custom Feed for Social Media N... |
| CVE-2023-5522 | MEDIUM | 4.3 | 0.4% | Oct 17, 2023 | Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post w... |
| CVE-2023-5339 | MEDIUM | 5.5 | 0.1% | Oct 17, 2023 | Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in loggin... |
| CVE-2023-45005 | MEDIUM | 6.1 | 0.3% | Oct 17, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Castos Seriously Simple Stats plugin <= 1.5.1 versions. |
| CVE-2023-44990 | MEDIUM | 4.8 | 0.3% | Oct 17, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Mana... |
| CVE-2023-44311 | MEDIUM | 6.1 | 0.5% | Oct 17, 2023 | Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplica... |
| CVE-2023-44310 | MEDIUM | 5.4 | 0.5% | Oct 17, 2023 | Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP... |
| CVE-2023-44309 | MEDIUM | 5.4 | 0.5% | Oct 17, 2023 | Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now