2023 CVE Vulnerabilities
31,401 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32976 | HIGH | 7.2 | 1.1% | Oct 13, 2023 | An OS command injection vulnerability has been reported to affect Container Station. If exploited, the vulnerability cou... |
| CVE-2023-32974 | HIGH | 7.5 | 0.6% | Oct 13, 2023 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul... |
| CVE-2023-32973 | HIGH | 7.2 | 0.5% | Oct 13, 2023 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2023-32970 | MEDIUM | 4.9 | 0.5% | Oct 13, 2023 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploite... |
| CVE-2023-5449 | LOW | 3.3 | 0.2% | Oct 13, 2023 | A potential security vulnerability has been identified in certain HP Displays supporting the Theft Deterrence feature wh... |
| CVE-2023-5409 | MEDIUM | 6.8 | 0.3% | Oct 13, 2023 | HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible t... |
| CVE-2023-4499 | HIGH | 7.5 | 0.5% | Oct 13, 2023 | A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and... |
| CVE-2023-45276 | HIGH | 8.8 | 0.2% | Oct 13, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in automatededitor.Com Automated Editor plugin <= 1.3 versions. |
| CVE-2023-45270 | HIGH | 8.8 | 0.2% | Oct 13, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.4.0 versions. |
| CVE-2023-45269 | MEDIUM | 5.4 | 0.2% | Oct 13, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 2.0.25 versions. |
| CVE-2023-40682 | MEDIUM | 4.4 | 0.2% | Oct 13, 2023 | IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local priv... |
| CVE-2023-45268 | HIGH | 8.8 | 0.2% | Oct 13, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Hitsteps Hitsteps Web Analytics plugin <= 5.86 versions. |
| CVE-2023-45267 | HIGH | 8.8 | 0.2% | Oct 13, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Zizou1988 IRivYou plugin <= 2.2.1 versions. |
| CVE-2023-41843 | MEDIUM | 5.4 | 0.5% | Oct 13, 2023 | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa... |
| CVE-2023-41836 | MEDIUM | 6.1 | 0.4% | Oct 13, 2023 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS... |
| CVE-2023-41682 | HIGH | 7.5 | 0.8% | Oct 13, 2023 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ... |
| CVE-2023-41681 | MEDIUM | 6.1 | 0.4% | Oct 13, 2023 | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa... |
| CVE-2023-41680 | MEDIUM | 6.1 | 0.5% | Oct 13, 2023 | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa... |
| CVE-2023-33303 | HIGH | 8.1 | 0.4% | Oct 13, 2023 | A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthoriz... |
| CVE-2023-45393 | MEDIUM | 6.5 | 0.5% | Oct 13, 2023 | An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to a... |
| CVE-2023-45391 | MEDIUM | 4.8 | 0.4% | Oct 13, 2023 | A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-... |
| CVE-2023-45109 | HIGH | 8.8 | 0.2% | Oct 13, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in ZAKSTAN WhitePage plugin <= 1.1.5 versions. |
| CVE-2023-5240 | HIGH | 7.5 | 0.6% | Oct 13, 2023 | Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with per... |
| CVE-2023-4995 | MEDIUM | 5.4 | 0.3% | Oct 13, 2023 | The Embed Calendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'calendly' shortcode in version... |
| CVE-2023-4829 | MEDIUM | 5.4 | 0.4% | Oct 13, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now