2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25488 | MEDIUM | 4.8 | 0.4% | Sep 1, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Duc Bui Quang WP Default Feature Image plugin <= 1.0.1... |
| CVE-2023-25477 | MEDIUM | 4.8 | 0.3% | Sep 1, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Yotuwp Video Gallery plugin <= 1.3.12 versions. |
| CVE-2023-25044 | MEDIUM | 4.8 | 0.3% | Sep 1, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions. |
| CVE-2023-25042 | MEDIUM | 4.8 | 0.3% | Sep 1, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy (Storm Consultancy) oAuth Twitter Feed for... |
| CVE-2023-24412 | MEDIUM | 4.8 | 0.3% | Sep 1, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Image Social Feed plugin <= 1.7.6 versions... |
| CVE-2023-1555 | MEDIUM | 4.3 | 0.4% | Sep 1, 2023 | An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting fr... |
| CVE-2023-1279 | MEDIUM | 6.1 | 0.3% | Sep 1, 2023 | An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting fro... |
| CVE-2023-0120 | MEDIUM | 4.3 | 0.4% | Sep 1, 2023 | An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting fr... |
| CVE-2023-4704 | MEDIUM | 4.9 | 0.7% | Sep 1, 2023 | External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
| CVE-2023-41364 | CRITICAL | 9.8 | 0.8% | Sep 1, 2023 | In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection. |
| CVE-2023-39685 | HIGH | 7.5 | 0.7% | Sep 1, 2023 | An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON str... |
| CVE-2023-24675 | MEDIUM | 4.8 | 0.5% | Sep 1, 2023 | Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories F... |
| CVE-2023-24674 | HIGH | 7.8 | 0.2% | Sep 1, 2023 | Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin p... |
| CVE-2023-4698 | HIGH | 7.5 | 0.8% | Sep 1, 2023 | Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2. |
| CVE-2023-4697 | HIGH | 8.8 | 0.7% | Sep 1, 2023 | Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2. |
| CVE-2023-4696 | CRITICAL | 9.8 | 0.9% | Sep 1, 2023 | Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. |
| CVE-2023-4695 | HIGH | 8.1 | 0.6% | Sep 1, 2023 | Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16. |
| CVE-2023-4481 | HIGH | 7.5 | 15.1% | Sep 1, 2023 | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos O... |
| CVE-2023-39912 | MEDIUM | 4.9 | 4.0% | Aug 31, 2023 | Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine wh... |
| CVE-2023-40576 | HIGH | 7.5 | 1.0% | Aug 31, 2023 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi... |
| CVE-2023-40575 | CRITICAL | 9.1 | 1.1% | Aug 31, 2023 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi... |
| CVE-2023-40574 | CRITICAL | 9.8 | 1.0% | Aug 31, 2023 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi... |
| CVE-2023-40569 | CRITICAL | 9.8 | 1.1% | Aug 31, 2023 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi... |
| CVE-2023-40567 | CRITICAL | 9.8 | 1.3% | Aug 31, 2023 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi... |
| CVE-2023-40188 | CRITICAL | 9.1 | 1.2% | Aug 31, 2023 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now