2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32598 | MEDIUM | 6.1 | 0.4% | Aug 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in A. R. Jones Featured Image Pro Post Grid plugin <= 5.14 ve... |
| CVE-2023-32596 | MEDIUM | 4.8 | 0.4% | Aug 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wolfgang Ertl weebotLite plugin <= 1.0.0 versions. |
| CVE-2023-32595 | MEDIUM | 4.8 | 0.4% | Aug 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Palasthotel by Edward Bock, Katharina Rompf Sunny Sear... |
| CVE-2023-32575 | MEDIUM | 4.8 | 0.4% | Aug 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for Wo... |
| CVE-2023-24394 | MEDIUM | 4.8 | 0.4% | Aug 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy iframe popup plugin <= 3.3 versions. |
| CVE-2023-4478 | HIGH | 8.2 | 0.4% | Aug 25, 2023 | Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to re... |
| CVE-2023-25981 | MEDIUM | 5.4 | 0.4% | Aug 25, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form plugin <= 2.8.1 versions. |
| CVE-2023-25649 | HIGH | 8.8 | 1.6% | Aug 25, 2023 | There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_D... |
| CVE-2023-3425 | MEDIUM | 5.3 | 0.5% | Aug 25, 2023 | Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS ... |
| CVE-2023-3406 | MEDIUM | 6.5 | 0.6% | Aug 25, 2023 | Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS... |
| CVE-2023-32591 | MEDIUM | 4.8 | 0.4% | Aug 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cloud Primero B.V DBargain plugin <= 3.0.0 versions. |
| CVE-2023-32584 | MEDIUM | 4.8 | 0.4% | Aug 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in John Newcombe eBecas plugin <= 3.1.3 versions. |
| CVE-2023-32577 | MEDIUM | 4.8 | 0.4% | Aug 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eji Osigwe DevBuddy Twitter Feed plugin <= 4.0.0 versi... |
| CVE-2023-32576 | MEDIUM | 5.4 | 0.4% | Aug 25, 2023 | Auth. (subscriber+) Stored Cross-Site Scripting') vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.18 v... |
| CVE-2023-32518 | MEDIUM | 6.1 | 0.4% | Aug 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ono Oogami WP Chinese Conversion plugin <= 1.1.16 versions... |
| CVE-2023-32757 | CRITICAL | 9.8 | 0.7% | Aug 25, 2023 | e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenti... |
| CVE-2023-32756 | HIGH | 7.5 | 0.9% | Aug 25, 2023 | e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An ... |
| CVE-2023-41173 | HIGH | 7.5 | 0.6% | Aug 25, 2023 | AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets. |
| CVE-2023-32755 | MEDIUM | 5.3 | 0.5% | Aug 25, 2023 | e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtai... |
| CVE-2023-40530 | MEDIUM | 4.7 | 0.5% | Aug 25, 2023 | Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skyl... |
| CVE-2023-4520 | MEDIUM | 6.1 | 0.5% | Aug 25, 2023 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_use... |
| CVE-2023-40599 | HIGH | 7.5 | 0.7% | Aug 25, 2023 | Regular expression Denial-of-Service (ReDoS) exists in multiple add-ons for Mailform Pro CGI 4.3.1.3 and earlier, which ... |
| CVE-2023-40577 | MEDIUM | 5.4 | 0.6% | Aug 25, 2023 | Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission t... |
| CVE-2023-40570 | MEDIUM | 5.3 | 0.5% | Aug 25, 2023 | Datasette is an open source multi-tool for exploring and publishing data. This bug affects Datasette instances running a... |
| CVE-2023-40217 | MEDIUM | 5.3 | 0.8% | Aug 25, 2023 | An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. I... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now