2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-44771 | MEDIUM | 5.4 | 0.5% | Oct 6, 2023 | A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code ... |
| CVE-2023-44770 | MEDIUM | 5.4 | 0.6% | Oct 6, 2023 | A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a... |
| CVE-2023-44766 | MEDIUM | 4.8 | 0.6% | Oct 6, 2023 | A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a cr... |
| CVE-2023-44765 | MEDIUM | 5.4 | 0.6% | Oct 6, 2023 | A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an at... |
| CVE-2023-44764 | MEDIUM | 5.4 | 0.5% | Oct 6, 2023 | A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installatio... |
| CVE-2023-44762 | MEDIUM | 5.4 | 0.6% | Oct 6, 2023 | A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute ar... |
| CVE-2023-44761 | MEDIUM | 5.4 | 0.5% | Oct 6, 2023 | Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 thr... |
| CVE-2023-40671 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in 大侠wp DX-auto-save-images plugin <= 1.4.0 versions. |
| CVE-2023-40008 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Gangesh Matta Simple Org Chart plugin <= 2.3.4 versions. |
| CVE-2023-27615 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Dipak C. Gajjar WP Super Minify plugin <= 1.5.1 versions. |
| CVE-2023-27448 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in MakeStories Team MakeStories (for Google Web Stories) plugin <= 2.8.0... |
| CVE-2023-25480 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Edi... |
| CVE-2023-25033 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Sumo Social Share Boost plugin <= 4.5 versions. |
| CVE-2023-36465 | HIGH | 7.1 | 0.5% | Oct 6, 2023 | Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City go... |
| CVE-2023-45246 | HIGH | 7.1 | 0.2% | Oct 6, 2023 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr... |
| CVE-2023-44758 | MEDIUM | 5.4 | 0.5% | Oct 6, 2023 | GDidees CMS 3.0 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary cod... |
| CVE-2023-4530 | CRITICAL | 9.8 | 0.5% | Oct 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Turna Advertising ... |
| CVE-2023-4469 | MEDIUM | 5.3 | 0.5% | Oct 6, 2023 | The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missi... |
| CVE-2023-45245 | MEDIUM | 5.5 | 0.2% | Oct 6, 2023 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux... |
| CVE-2023-45244 | HIGH | 7.1 | 0.2% | Oct 6, 2023 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr... |
| CVE-2023-5312 | — | — | — | Oct 6, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-43226. Reason: This candidate is a ... |
| CVE-2023-40556 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions. |
| CVE-2023-26153 | CRITICAL | 9.8 | 3.2% | Oct 6, 2023 | Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of Y... |
| CVE-2023-45243 | MEDIUM | 5.5 | 0.2% | Oct 5, 2023 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protec... |
| CVE-2023-45242 | MEDIUM | 5.5 | 0.2% | Oct 5, 2023 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protec... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now