2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25019 | MEDIUM | 6.1 | 0.4% | Aug 30, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premio Chaty plugin <= 3.0.9 versions |
| CVE-2023-32740 | MEDIUM | 6.1 | 0.3% | Aug 30, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.8.1 versions. |
| CVE-2023-3136 | MEDIUM | 6.1 | 0.4% | Aug 30, 2023 | The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up t... |
| CVE-2023-4522 | MEDIUM | 5.3 | 0.9% | Aug 30, 2023 | An issue has been discovered in GitLab affecting all versions before 16.2.0. Committing directories containing LF charac... |
| CVE-2023-4609 | — | — | — | Aug 30, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-4599 | MEDIUM | 5.4 | 0.4% | Aug 30, 2023 | The Email Encoder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in ve... |
| CVE-2023-4597 | MEDIUM | 6.4 | 0.6% | Aug 30, 2023 | The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slimstat' shortcode in... |
| CVE-2023-4596 | CRITICAL | 9.8 | 12.7% | Aug 30, 2023 | The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after ... |
| CVE-2023-4526 | — | — | — | Aug 30, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-4525 | — | — | — | Aug 30, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-41269 | — | — | — | Aug 30, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-41266 | MEDIUM | 6.5 | 82.1% | Aug 29, 2023 | A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, Feb... |
| CVE-2023-41265 | CRITICAL | 9.9 | 84.5% | Aug 29, 2023 | An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and ear... |
| CVE-2023-39559 | MEDIUM | 5.3 | 0.6% | Aug 29, 2023 | AudimexEE 15.0 was discovered to contain a full path disclosure vulnerability. |
| CVE-2023-39558 | MEDIUM | 6.1 | 0.4% | Aug 29, 2023 | AudimexEE v15.0 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the Show Kai... |
| CVE-2023-4611 | MEDIUM | 6.3 | 0.3% | Aug 29, 2023 | A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is ... |
| CVE-2023-4296 | MEDIUM | 6.1 | 0.6% | Aug 29, 2023 | If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to i... |
| CVE-2023-41153 | MEDIUM | 5.4 | 0.4% | Aug 29, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers ... |
| CVE-2023-38975 | HIGH | 7.5 | 0.8% | Aug 29, 2023 | * Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_ve... |
| CVE-2023-38971 | MEDIUM | 5.4 | 0.6% | Aug 29, 2023 | Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via... |
| CVE-2023-32241 | MEDIUM | 6.1 | 0.4% | Aug 29, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPDeveloper Essential Addons for Elementor Pro plugin <= 5... |
| CVE-2023-4572 | HIGH | 8.8 | 0.9% | Aug 29, 2023 | Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to potentially exploit ... |
| CVE-2023-4346 | HIGH | 7.5 | 0.5% | Aug 29, 2023 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable... |
| CVE-2023-3253 | MEDIUM | 4.3 | 0.4% | Aug 29, 2023 | An improper authorization vulnerability exists where an authenticated, low privileged remote attacker could view a list... |
| CVE-2023-39678 | MEDIUM | 6.1 | 0.4% | Aug 29, 2023 | A cross-site scripting (XSS) vulnerability in the device web interface (Log Query page) of BDCOM OLT P3310D-2AC 10.1.0F ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now