2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27435 | HIGH | 8.8 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui HTTP Auth plugin <= 0.3.2 versions. |
| CVE-2023-0506 | HIGH | 8.8 | 0.5% | Oct 3, 2023 | The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation... |
| CVE-2023-5353 | MEDIUM | 6.5 | 0.6% | Oct 3, 2023 | Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1. |
| CVE-2023-42508 | MEDIUM | 6.5 | 0.4% | Oct 3, 2023 | JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, whi... |
| CVE-2023-40212 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versio... |
| CVE-2023-40202 | HIGH | 8.8 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Hannes Etzelstorfer // codemiq WP HTML Mail plugin <= 3.4.1 versions. |
| CVE-2023-40201 | HIGH | 8.8 | 0.3% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in FuturioWP Futurio Extra plugin <= 1.8.4 versions leads to activation ... |
| CVE-2023-40199 | HIGH | 8.8 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab WP Like Button plugin <= 1.7.0 versions. |
| CVE-2023-40198 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Antsanchez Easy Cookie Law plugin <= 3.1 versions. |
| CVE-2023-40009 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Pipes plugin <= 1.4.0 versions. |
| CVE-2023-39159 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Fraud Prevention For Woocommerce plugin <= 2.1.5 versions... |
| CVE-2023-32792 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker... |
| CVE-2023-32791 | MEDIUM | 6.5 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker... |
| CVE-2023-32790 | MEDIUM | 6.1 | 0.3% | Oct 3, 2023 | Cross-Site Scripting (XSS) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to inj... |
| CVE-2023-32671 | MEDIUM | 5.4 | 0.3% | Oct 3, 2023 | A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an at... |
| CVE-2023-32670 | MEDIUM | 5.4 | 0.4% | Oct 3, 2023 | Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privile... |
| CVE-2023-32669 | MEDIUM | 5.4 | 0.3% | Oct 3, 2023 | Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated us... |
| CVE-2023-2681 | HIGH | 8.8 | 0.6% | Oct 3, 2023 | An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote... |
| CVE-2023-5351 | MEDIUM | 5.4 | 0.5% | Oct 3, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1. |
| CVE-2023-5350 | CRITICAL | 9.1 | 1.9% | Oct 3, 2023 | SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1. |
| CVE-2023-4103 | HIGH | 8.8 | 0.5% | Oct 3, 2023 | QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not c... |
| CVE-2023-4102 | HIGH | 8.8 | 0.6% | Oct 3, 2023 | QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficien... |
| CVE-2023-4101 | MEDIUM | 6.5 | 0.4% | Oct 3, 2023 | The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has suffi... |
| CVE-2023-4100 | HIGH | 8.2 | 0.3% | Oct 3, 2023 | Allows an attacker to perform XSS attacks stored on certain resources. Exploiting this vulnerability can lead to a DoS c... |
| CVE-2023-4099 | MEDIUM | 6.5 | 0.3% | Oct 3, 2023 | The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now