2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31071 | MEDIUM | 6.1 | 0.4% | Aug 17, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yannick Lefebvre Modal Dialog plugin <= 3.5.14 versions. |
| CVE-2023-30877 | MEDIUM | 6.1 | 0.4% | Aug 17, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov XML for Google Merchant Center plugin <= 3.... |
| CVE-2023-30876 | MEDIUM | 4.8 | 0.4% | Aug 17, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dave Ross Dave's WordPress Live Search plugin <= 4.8.1... |
| CVE-2023-30874 | MEDIUM | 4.8 | 0.4% | Aug 17, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Steve Curtis, St. Pete Design Gps Plotter plugin <= 5.... |
| CVE-2023-28622 | MEDIUM | 5.4 | 0.4% | Aug 17, 2023 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Trident Technolabs Easy Slider Revolution plugin <= 1... |
| CVE-2023-28533 | MEDIUM | 4.8 | 0.4% | Aug 17, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in M Williams Cab Grid plugin <= 1.5.15 versions. |
| CVE-2023-40281 | MEDIUM | 4.8 | 0.4% | Aug 17, 2023 | EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Ma... |
| CVE-2023-40252 | CRITICAL | 9.8 | 0.4% | Aug 17, 2023 | Improper Control of Generation of Code ('Code Injection') vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V... |
| CVE-2023-40251 | MEDIUM | 5.9 | 0.1% | Aug 17, 2023 | Missing Encryption of Sensitive Data vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian N... |
| CVE-2023-3244 | MEDIUM | 4.3 | 0.8% | Aug 17, 2023 | The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2023-34217 | HIGH | 8.1 | 0.4% | Aug 17, 2023 | TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to ... |
| CVE-2023-34216 | HIGH | 8.1 | 0.6% | Aug 17, 2023 | TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to ... |
| CVE-2023-34215 | CRITICAL | 9.8 | 0.6% | Aug 17, 2023 | TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerabilit... |
| CVE-2023-4395 | MEDIUM | 5.4 | 0.5% | Aug 17, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4. |
| CVE-2023-4392 | MEDIUM | 5.3 | 0.5% | Aug 17, 2023 | A vulnerability was found in Control iD Gerencia Web 1.30 and classified as problematic. Affected by this issue is some ... |
| CVE-2023-34214 | CRITICAL | 9.8 | 0.4% | Aug 17, 2023 | TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to ... |
| CVE-2023-34213 | CRITICAL | 9.8 | 0.6% | Aug 17, 2023 | TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability st... |
| CVE-2023-33239 | CRITICAL | 9.8 | 1.1% | Aug 17, 2023 | TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to ... |
| CVE-2023-33238 | CRITICAL | 9.8 | 0.7% | Aug 17, 2023 | TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to ... |
| CVE-2023-25647 | LOW | 3.3 | 0.2% | Aug 17, 2023 | There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, app... |
| CVE-2023-33237 | HIGH | 8.8 | 0.5% | Aug 17, 2023 | TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerabilit... |
| CVE-2023-35011 | MEDIUM | 5.4 | 0.4% | Aug 16, 2023 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an a... |
| CVE-2023-35009 | MEDIUM | 5.3 | 0.8% | Aug 16, 2023 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authe... |
| CVE-2023-39846 | CRITICAL | 9.8 | 0.9% | Aug 16, 2023 | An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token. |
| CVE-2023-38894 | CRITICAL | 9.8 | 1.7% | Aug 16, 2023 | A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code vi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now