2023 CVE Vulnerabilities
31,401 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-45807 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana following the license change in early 202... |
| CVE-2023-45540 | MEDIUM | 6.5 | 0.5% | Oct 16, 2023 | An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted s... |
| CVE-2023-45131 | HIGH | 7.5 | 1.8% | Oct 16, 2023 | Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticate... |
| CVE-2023-44394 | MEDIUM | 4.3 | 0.6% | Oct 16, 2023 | MantisBT is an open source bug tracker. Due to insufficient access-level checks on the Wiki redirection page, any user c... |
| CVE-2023-44391 | MEDIUM | 5.3 | 0.4% | Oct 16, 2023 | Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even wh... |
| CVE-2023-44388 | HIGH | 7.5 | 0.5% | Oct 16, 2023 | Discourse is an open source platform for community discussion. A malicious request can cause production log files to qui... |
| CVE-2023-43814 | LOW | 3.7 | 0.3% | Oct 16, 2023 | Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can ... |
| CVE-2023-43659 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Sc... |
| CVE-2023-43658 | MEDIUM | 6.1 | 0.5% | Oct 16, 2023 | dicourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar i... |
| CVE-2023-38740 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a spec... |
| CVE-2023-38728 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic... |
| CVE-2023-45542 | MEDIUM | 6.1 | 1.6% | Oct 16, 2023 | Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a cra... |
| CVE-2023-45147 | LOW | 3.1 | 0.3% | Oct 16, 2023 | Discourse is an open source community platform. In affected versions any user can create a topic and add arbitrary custo... |
| CVE-2023-45144 | CRITICAL | 9.6 | 1.1% | Oct 16, 2023 | com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth... |
| CVE-2023-45141 | HIGH | 8.8 | 0.3% | Oct 16, 2023 | Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been ide... |
| CVE-2023-45128 | HIGH | 8.8 | 0.3% | Oct 16, 2023 | Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been ide... |
| CVE-2023-42459 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). I... |
| CVE-2023-40852 | CRITICAL | 9.8 | 0.8% | Oct 16, 2023 | SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allo... |
| CVE-2023-40851 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin p... |
| CVE-2023-38720 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 and 11.5 is vulnerable to denial of service with ... |
| CVE-2023-30987 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic... |
| CVE-2023-5561 | MEDIUM | 5.3 | 3.9% | Oct 16, 2023 | WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attacke... |
| CVE-2023-5177 | MEDIUM | 5.3 | 0.5% | Oct 16, 2023 | The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 exposes the full path of a file when putting in a non-existen... |
| CVE-2023-5167 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activi... |
| CVE-2023-5133 | HIGH | 7.5 | 0.5% | Oct 16, 2023 | This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted header... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now