2023 CVE Vulnerabilities
31,401 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42629 | MEDIUM | 5.4 | 2.2% | Oct 17, 2023 | Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, ... |
| CVE-2023-24385 | MEDIUM | 4.8 | 0.3% | Oct 17, 2023 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in David Lingren Media Library Assistant plugin <= 3.11 ... |
| CVE-2023-4399 | HIGH | 7.2 | 1.1% | Oct 17, 2023 | Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny... |
| CVE-2023-42497 | MEDIUM | 6.1 | 0.5% | Oct 17, 2023 | Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through ... |
| CVE-2023-4089 | LOW | 2.7 | 0.5% | Oct 17, 2023 | On affected Wago products an remote attacker with administrative privileges can access files to which he has already acc... |
| CVE-2023-41752 | HIGH | 7.5 | 1.2% | Oct 17, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apa... |
| CVE-2023-39456 | HIGH | 7.5 | 53.5% | Oct 17, 2023 | Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache ... |
| CVE-2023-44694 | CRITICAL | 9.8 | 0.7% | Oct 17, 2023 | D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /log/mailrecvview.php. |
| CVE-2023-44693 | CRITICAL | 9.8 | 13.3% | Oct 17, 2023 | D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php. |
| CVE-2023-45386 | CRITICAL | 9.8 | 0.6% | Oct 17, 2023 | In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via `... |
| CVE-2023-45375 | HIGH | 8.8 | 38.5% | Oct 17, 2023 | In the module "PireosPay" (pireospay) before version 1.7.10 from 01generator.com for PrestaShop, a guest can perform SQL... |
| CVE-2023-45358 | MEDIUM | 5.4 | 0.4% | Oct 17, 2023 | Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote... |
| CVE-2023-45357 | MEDIUM | 6.5 | 0.5% | Oct 17, 2023 | Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authen... |
| CVE-2023-34210 | HIGH | 8.8 | 0.6% | Oct 17, 2023 | SQL Injection in create customer group function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticat... |
| CVE-2023-34209 | MEDIUM | 4.3 | 0.4% | Oct 17, 2023 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in create template function in EasyUse MailHu... |
| CVE-2023-34208 | MEDIUM | 6.5 | 0.6% | Oct 17, 2023 | Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated us... |
| CVE-2023-34207 | HIGH | 8.8 | 0.6% | Oct 17, 2023 | Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate... |
| CVE-2023-4215 | HIGH | 7.5 | 0.5% | Oct 17, 2023 | Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability t... |
| CVE-2023-45659 | LOW | 2.8 | 0.2% | Oct 17, 2023 | Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained acc... |
| CVE-2023-45152 | LOW | 2.3 | 0.3% | Oct 17, 2023 | Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it po... |
| CVE-2023-40373 | HIGH | 7.5 | 0.8% | Oct 17, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially cr... |
| CVE-2023-40372 | HIGH | 7.5 | 0.8% | Oct 17, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special... |
| CVE-2023-38719 | MEDIUM | 4.4 | 0.2% | Oct 17, 2023 | IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation ... |
| CVE-2023-40374 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special... |
| CVE-2023-30991 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now