2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28994MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UX-themes Flatsome plugin <= 3.16.8 versions.
CVE-2023-32499MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tony Zeoli, Tony Hayes Radio Station by netmix® – Manage a...
CVE-2023-32498MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Easy Form team Easy Form by AYS plugin <= 1.2.0 versio...
CVE-2023-32497MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Supersoju Block Referer Spam plugin <= 1.1.9.4 version...
CVE-2023-32496MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bill Minozzi Block Bad Bots and Stop Bad Bots Crawlers...
CVE-2023-32236MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking C...
CVE-2023-4042MEDIUM5.5A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisor...
CVE-2023-32119MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin ...
CVE-2023-3899HIGH7.8A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization...
CVE-2023-41105HIGH7.5An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), ...
CVE-2023-41104MEDIUM6.5libvmod-digest before 1.0.3, as used in Varnish Enterprise 6.0.x before 6.0.11r5, has an out-of-bounds memory access dur...
CVE-2023-41100MEDIUM5.3An issue was discovered in the hcaptcha (aka hCaptcha for EXT:form) extension before 2.1.2 for TYPO3. It fails to check ...
CVE-2023-41098MEDIUM6.1An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via th...
CVE-2023-4041CRITICAL9.8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without In...
CVE-2023-40282MEDIUM5.4Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in t...
CVE-2023-40144HIGH8.8OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS...
CVE-2023-40158HIGH8.8Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS...
CVE-2023-38585HIGH8.8Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary...
CVE-2023-4404CRITICAL9.8The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu...
CVE-2023-3495HIGH7.8** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (KeypadDesigner) allows local attac...
CVE-2023-39986MEDIUM5.5** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Read vulnerability in Hitachi EH-VIEW (Designer) allows local attackers to...
CVE-2023-39985HIGH7.8** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (Designer) allows local attackers t...
CVE-2023-39984HIGH7.8** UNSUPPORTED WHEN ASSIGNED ** Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in...
CVE-2023-4431HIGH8.1Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an ou...
CVE-2023-4430HIGH8.8Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now