2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2188 | MEDIUM | 4.9 | 0.8% | Aug 31, 2023 | The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and... |
| CVE-2023-2174 | MEDIUM | 4.3 | 0.3% | Aug 31, 2023 | The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2023-2173 | MEDIUM | 4.3 | 0.4% | Aug 31, 2023 | The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7... |
| CVE-2023-2172 | MEDIUM | 4.3 | 0.4% | Aug 31, 2023 | The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7... |
| CVE-2023-2171 | MEDIUM | 5.4 | 0.3% | Aug 31, 2023 | The BadgeOS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions ... |
| CVE-2023-0689 | MEDIUM | 4.3 | 0.5% | Aug 31, 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name'... |
| CVE-2023-4655 | MEDIUM | 6.1 | 0.4% | Aug 31, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1. |
| CVE-2023-4654 | LOW | 3.5 | 0.3% | Aug 31, 2023 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1. |
| CVE-2023-4653 | MEDIUM | 4.8 | 0.4% | Aug 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
| CVE-2023-4652 | MEDIUM | 5.4 | 0.4% | Aug 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
| CVE-2023-4651 | MEDIUM | 5.4 | 0.3% | Aug 31, 2023 | Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1. |
| CVE-2023-4650 | MEDIUM | 4.7 | 0.5% | Aug 31, 2023 | Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
| CVE-2023-4649 | MEDIUM | 5.4 | 0.4% | Aug 31, 2023 | Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1. |
| CVE-2023-4163 | MEDIUM | 4.4 | 0.3% | Aug 31, 2023 | In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, le... |
| CVE-2023-4162 | MEDIUM | 4.4 | 0.2% | Aug 31, 2023 | A segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a ... |
| CVE-2023-31925 | MEDIUM | 6.5 | 0.2% | Aug 31, 2023 | Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A privileged user could ... |
| CVE-2023-31424 | CRITICAL | 9.8 | 0.7% | Aug 31, 2023 | Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web... |
| CVE-2023-31423 | MEDIUM | 5.5 | 0.2% | Aug 31, 2023 | Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration ... |
| CVE-2023-3489 | HIGH | 7.5 | 0.3% | Aug 31, 2023 | The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in t... |
| CVE-2023-23765 | MEDIUM | 6.5 | 0.5% | Aug 30, 2023 | An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displa... |
| CVE-2023-41163 | MEDIUM | 6.1 | 0.4% | Aug 30, 2023 | A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to... |
| CVE-2023-41041 | LOW | 3.1 | 0.4% | Aug 30, 2023 | Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged ... |
| CVE-2023-41040 | MEDIUM | 6.5 | 1.0% | Aug 30, 2023 | GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython... |
| CVE-2023-39139 | HIGH | 7.8 | 0.3% | Aug 30, 2023 | An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file. |
| CVE-2023-39138 | HIGH | 7.8 | 0.4% | Aug 30, 2023 | An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now