2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38558 | MEDIUM | 5.5 | 0.2% | Sep 14, 2023 | A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Ad... |
| CVE-2023-38557 | HIGH | 7.8 | 0.1% | Sep 14, 2023 | A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper ac... |
| CVE-2023-4516 | HIGH | 7.8 | 0.2% | Sep 14, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allo... |
| CVE-2023-42503 | MEDIUM | 5.5 | 0.5% | Sep 14, 2023 | Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.Thi... |
| CVE-2023-41267 | HIGH | 7.8 | 0.5% | Sep 14, 2023 | In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect... |
| CVE-2023-38206 | MEDIUM | 5.3 | 0.6% | Sep 14, 2023 | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improp... |
| CVE-2023-38205 | HIGH | 7.5 | 99.7% | Sep 14, 2023 | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improp... |
| CVE-2023-38204 | CRITICAL | 9.8 | 65.5% | Sep 14, 2023 | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deseria... |
| CVE-2023-4814 | HIGH | 7.1 | 0.1% | Sep 14, 2023 | A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete a... |
| CVE-2023-26141 | MEDIUM | 4.9 | 0.8% | Sep 14, 2023 | Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the... |
| CVE-2023-4948 | MEDIUM | 4.3 | 0.3% | Sep 14, 2023 | The WooCommerce CVR Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2023-4945 | MEDIUM | 5.4 | 0.5% | Sep 14, 2023 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in... |
| CVE-2023-4944 | MEDIUM | 5.4 | 0.4% | Sep 14, 2023 | The Awesome Weather Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' short... |
| CVE-2023-4841 | MEDIUM | 5.4 | 0.5% | Sep 14, 2023 | The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in ... |
| CVE-2023-23845 | HIGH | 7.2 | 5.4% | Sep 13, 2023 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ... |
| CVE-2023-23840 | HIGH | 7.2 | 5.4% | Sep 13, 2023 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ... |
| CVE-2023-41162 | MEDIUM | 6.1 | 0.4% | Sep 13, 2023 | A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to... |
| CVE-2023-41158 | MEDIUM | 5.4 | 0.4% | Sep 13, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers... |
| CVE-2023-41155 | MEDIUM | 5.4 | 0.4% | Sep 13, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the mail forwarding and replies tab in Webmin and Usermin 2.000 all... |
| CVE-2023-41154 | MEDIUM | 5.4 | 0.4% | Sep 13, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the scheduled cron jobs tab in Usermin 2.000 allows remote attacker... |
| CVE-2023-41152 | MEDIUM | 5.4 | 0.4% | Sep 13, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers... |
| CVE-2023-40617 | MEDIUM | 6.1 | 0.5% | Sep 13, 2023 | A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execut... |
| CVE-2023-4568 | MEDIUM | 6.5 | 3.6% | Sep 13, 2023 | PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to... |
| CVE-2023-42468 | MEDIUM | 5.3 | 0.9% | Sep 13, 2023 | The com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls ... |
| CVE-2023-41892 | CRITICAL | 9.8 | 92.9% | Sep 13, 2023 | Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users run... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now