2023 CVE Vulnerabilities
31,401 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4388 | MEDIUM | 4.8 | 0.4% | Oct 16, 2023 | The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privil... |
| CVE-2023-4290 | MEDIUM | 6.1 | 0.4% | Oct 16, 2023 | The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting i... |
| CVE-2023-4289 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The WP Matterport Shortcode WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes ... |
| CVE-2023-45150 | MEDIUM | 4.3 | 0.4% | Oct 16, 2023 | Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server wa... |
| CVE-2023-45149 | MEDIUM | 4.3 | 0.5% | Oct 16, 2023 | Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection of public... |
| CVE-2023-43121 | HIGH | 7.5 | 1.0% | Oct 16, 2023 | A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.... |
| CVE-2023-43119 | CRITICAL | 9.8 | 0.6% | Oct 16, 2023 | An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 ... |
| CVE-2023-43118 | HIGH | 8.8 | 0.3% | Oct 16, 2023 | Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32... |
| CVE-2023-3746 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allo... |
| CVE-2023-3707 | MEDIUM | 4.3 | 0.5% | Oct 16, 2023 | The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong t... |
| CVE-2023-3706 | MEDIUM | 4.3 | 0.5% | Oct 16, 2023 | The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to ... |
| CVE-2023-3279 | MEDIUM | 4.9 | 0.8% | Oct 16, 2023 | The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to g... |
| CVE-2023-3155 | HIGH | 7.2 | 0.8% | Oct 16, 2023 | The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack ... |
| CVE-2023-3154 | HIGH | 7.5 | 0.7% | Oct 16, 2023 | The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input p... |
| CVE-2023-29484 | MEDIUM | 6.5 | 0.3% | Oct 16, 2023 | In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password. |
| CVE-2023-45683 | MEDIUM | 6.1 | 0.4% | Oct 16, 2023 | github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the AC... |
| CVE-2023-45669 | MEDIUM | 5.3 | 0.5% | Oct 16, 2023 | WebAuthn4J Spring Security provides Web Authentication specification support for Spring applications. Affected versions ... |
| CVE-2023-45660 | MEDIUM | 4.3 | 0.6% | Oct 16, 2023 | Nextcloud mail is an email app for the Nextcloud home server platform. In affected versions a missing check of origin, t... |
| CVE-2023-45151 | HIGH | 8.8 | 0.5% | Oct 16, 2023 | Nextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext... |
| CVE-2023-45148 | MEDIUM | 4.3 | 0.7% | Oct 16, 2023 | Nextcloud is an open source home cloud server. When Memcached is used as `memcache.distributed` the rate limiting in Nex... |
| CVE-2023-43120 | HIGH | 8.8 | 0.7% | Oct 16, 2023 | An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attac... |
| CVE-2023-40180 | HIGH | 7.5 | 0.9% | Oct 16, 2023 | silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a re... |
| CVE-2023-45985 | HIGH | 7.5 | 0.7% | Oct 16, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack ove... |
| CVE-2023-45984 | CRITICAL | 9.8 | 0.7% | Oct 16, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack over... |
| CVE-2023-45690 | MEDIUM | 4.9 | 1.5% | Oct 16, 2023 | Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user that's aut... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now