2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2358 | MEDIUM | 4.9 | 0.2% | Sep 27, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.5.0.0 and 9.3.0.4, including 8.3.x.x, saves passw... |
| CVE-2023-2315 | HIGH | 8.8 | 0.8% | Sep 27, 2023 | Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the ... |
| CVE-2023-29497 | LOW | 3.3 | 0.2% | Sep 27, 2023 | A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app ... |
| CVE-2023-28790 | MEDIUM | 4.8 | 0.3% | Sep 27, 2023 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Brett Shumaker Simple Staff List plugin <= 2.2.3 vers... |
| CVE-2023-28490 | MEDIUM | 6.1 | 0.4% | Sep 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versio... |
| CVE-2023-28055 | HIGH | 8.8 | 0.3% | Sep 27, 2023 | Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated at... |
| CVE-2023-27628 | MEDIUM | 5.4 | 0.3% | Sep 27, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Webvitaly Sitekit plugin <= 1.3 versions. |
| CVE-2023-27622 | MEDIUM | 4.8 | 0.3% | Sep 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Abel Ruiz GuruWalk Affiliates plugin <= 1.0.0 versions... |
| CVE-2023-27617 | MEDIUM | 4.8 | 0.3% | Sep 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions. |
| CVE-2023-27616 | MEDIUM | 6.1 | 0.3% | Sep 27, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions. |
| CVE-2023-25483 | MEDIUM | 4.8 | 0.3% | Sep 27, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ankit Agarwal, Priyanshu Mittal Easy Coming Soon plugi... |
| CVE-2023-23958 | MEDIUM | 6.5 | 0.5% | Sep 27, 2023 | Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability. |
| CVE-2023-23495 | MEDIUM | 5.5 | 0.2% | Sep 27, 2023 | A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma ... |
| CVE-2023-0833 | MEDIUM | 5.5 | 0.4% | Sep 27, 2023 | A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure ... |
| CVE-2023-0456 | HIGH | 7.5 | 0.6% | Sep 27, 2023 | A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token fro... |
| CVE-2023-4259 | HIGH | 8.8 | 0.7% | Sep 26, 2023 | Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code. |
| CVE-2023-43325 | MEDIUM | 6.1 | 1.9% | Sep 26, 2023 | A reflected cross-site scripting (XSS) vulnerability in the data[redirect_url] parameter of mooSocial v3.1.8 allows atta... |
| CVE-2023-43278 | HIGH | 8.8 | 0.3% | Sep 25, 2023 | A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an ad... |
| CVE-2023-38907 | HIGH | 7.5 | 0.7% | Sep 25, 2023 | An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, a... |
| CVE-2023-4258 | MEDIUM | 6.5 | 0.5% | Sep 25, 2023 | In Bluetooth mesh implementation If provisionee has a public key that is sent OOB then during provisioning it can be sen... |
| CVE-2023-43326 | MEDIUM | 6.1 | 1.6% | Sep 25, 2023 | A reflected cross-site scripting (XSS) vulnerability exisits in multiple url of mooSocial v3.1.8 allows attackers to ste... |
| CVE-2023-5129 | — | — | — | Sep 25, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate of CVE-2023-4863. |
| CVE-2023-43457 | CRITICAL | 9.8 | 1.0% | Sep 25, 2023 | An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in... |
| CVE-2023-43132 | MEDIUM | 6.5 | 0.6% | Sep 25, 2023 | szvone vmqphp <=1.13 is vulnerable to SQL Injection. Unauthorized remote users can use sql injection attacks to obtain t... |
| CVE-2023-42753 | HIGH | 7.8 | 0.5% | Sep 25, 2023 | An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now