2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-42426 | MEDIUM | 6.1 | 1.1% | Sep 25, 2023 | Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary co... |
| CVE-2023-43644 | CRITICAL | 9.8 | 0.7% | Sep 25, 2023 | Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafte... |
| CVE-2023-43642 | HIGH | 7.5 | 1.0% | Sep 25, 2023 | snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream ... |
| CVE-2023-43458 | MEDIUM | 5.4 | 0.5% | Sep 25, 2023 | Cross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrar... |
| CVE-2023-43319 | MEDIUM | 6.1 | 0.4% | Sep 25, 2023 | Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arb... |
| CVE-2023-42817 | MEDIUM | 5.4 | 0.3% | Sep 25, 2023 | Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from ... |
| CVE-2023-41871 | MEDIUM | 6.1 | 0.3% | Sep 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Poll Maker Team Poll Maker plugin <= 4.7.0 versions. |
| CVE-2023-41868 | MEDIUM | 6.1 | 0.3% | Sep 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ram Ratan Maurya, Codestag StagTools plugin <= 2.3.7 versi... |
| CVE-2023-41867 | MEDIUM | 6.1 | 0.3% | Sep 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AcyMailing Newsletter Team AcyMailing plugin <= 8.6.2 vers... |
| CVE-2023-41863 | MEDIUM | 6.1 | 0.3% | Sep 25, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Pepro Dev. Group PeproDev CF7 Database plugin <= 1.7.0 versio... |
| CVE-2023-40581 | HIGH | 7.8 | 1.3% | Sep 25, 2023 | yt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp allows the user to provide shell command lines to... |
| CVE-2023-39640 | CRITICAL | 9.8 | 0.5% | Sep 25, 2023 | UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHoo... |
| CVE-2023-4156 | HIGH | 7.1 | 0.4% | Sep 25, 2023 | A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be u... |
| CVE-2023-5166 | MEDIUM | 6.5 | 0.7% | Sep 25, 2023 | Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desk... |
| CVE-2023-5165 | HIGH | 8.8 | 0.2% | Sep 25, 2023 | Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via t... |
| CVE-2023-5158 | MEDIUM | 5.5 | 0.2% | Sep 25, 2023 | A flaw was found in vringh_kiov_advance in drivers/vhost/vringh.c in the host side of a virtio ring in the Linux Kernel.... |
| CVE-2023-5156 | HIGH | 7.5 | 1.3% | Sep 25, 2023 | A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which ... |
| CVE-2023-4892 | MEDIUM | 4.6 | 0.4% | Sep 25, 2023 | Teedy v1.11 has a vulnerability in its text editor that allows events to be executed in HTML tags that an attacker coul... |
| CVE-2023-4631 | MEDIUM | 5.3 | 0.6% | Sep 25, 2023 | The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of ... |
| CVE-2023-4549 | MEDIUM | 6.1 | 0.6% | Sep 25, 2023 | The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For... |
| CVE-2023-4521 | CRITICAL | 9.8 | 39.6% | Sep 25, 2023 | The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to p... |
| CVE-2023-4502 | MEDIUM | 4.8 | 0.4% | Sep 25, 2023 | The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings,... |
| CVE-2023-4490 | CRITICAL | 9.8 | 3.1% | Sep 25, 2023 | The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statem... |
| CVE-2023-4476 | MEDIUM | 6.1 | 0.4% | Sep 25, 2023 | The Locatoraid Store Locator WordPress plugin before 3.9.24 does not sanitise and escape the lpr-search parameter before... |
| CVE-2023-4300 | HIGH | 7.2 | 1.7% | Sep 25, 2023 | The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now