2023 CVE Vulnerabilities

31,401 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45905HIGH8.8Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add.
CVE-2023-45904HIGH8.8Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update.
CVE-2023-45903HIGH8.8Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete.
CVE-2023-45902HIGH8.8Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/del...
CVE-2023-45901HIGH8.8Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\/category\/add...
CVE-2023-43959HIGH8.8An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted ...
CVE-2023-20598HIGH7.8 An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an I...
CVE-2023-44824HIGH7.8An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploade...
CVE-2023-43777MEDIUM6.5Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining param...
CVE-2023-43776MEDIUM6.6Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unautho...
CVE-2023-42627MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3....
CVE-2023-45007MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Fotomoto plugin <= 1.2.8 versions.
CVE-2023-45006MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ByConsole WooODT Lite – WooCommerce Order Delivery or Pick...
CVE-2023-45004MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wp3sixty Woo Custom Emails plugin <= 2.2 versions.
CVE-2023-42628MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay...
CVE-2023-39902HIGH7.8A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i...
CVE-2023-45010MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex MacArthur Complete Open Graph plugin <= 3.4.5 ver...
CVE-2023-45003MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins Social Feed | Custom Feed for Social Media N...
CVE-2023-5522MEDIUM4.3Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post w...
CVE-2023-5339MEDIUM5.5Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in loggin...
CVE-2023-45005MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Castos Seriously Simple Stats plugin <= 1.5.1 versions.
CVE-2023-44990MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Mana...
CVE-2023-44311MEDIUM6.1Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplica...
CVE-2023-44310MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP...
CVE-2023-44309MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now