2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29437 | MEDIUM | 5.4 | 0.4% | Jun 26, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Steven A. Zahm Connections Business Directory pl... |
| CVE-2023-36631 | HIGH | 7.8 | 0.6% | Jun 26, 2023 | Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged us... |
| CVE-2023-29435 | MEDIUM | 5.4 | 0.4% | Jun 26, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Zwaply Cryptocurrency All-in-One plugin <= 3.0.1... |
| CVE-2023-3398 | HIGH | 7.5 | 0.8% | Jun 26, 2023 | Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3. |
| CVE-2023-29436 | MEDIUM | 5.4 | 0.4% | Jun 26, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Flyn San IFrame Shortcode plugin <= 1.0.5 versio... |
| CVE-2023-29434 | MEDIUM | 4.8 | 0.4% | Jun 26, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in FancyThemes Optin Forms – Simple List Building Plugin ... |
| CVE-2023-29430 | MEDIUM | 6.1 | 0.4% | Jun 26, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CTHthemes TheRoof theme <= 1.0.3 versions. |
| CVE-2023-29427 | MEDIUM | 6.1 | 0.4% | Jun 26, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in TMS Booking for Appointments and Events Calendar – Amelia ... |
| CVE-2023-29424 | MEDIUM | 4.8 | 0.3% | Jun 26, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Plainware ShiftController Employee Shift Scheduling pl... |
| CVE-2023-29423 | MEDIUM | 4.8 | 0.4% | Jun 26, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Cancel order request / Return order / R... |
| CVE-2023-22359 | MEDIUM | 4.3 | 0.4% | Jun 26, 2023 | User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames. |
| CVE-2023-1620 | MEDIUM | 4.9 | 0.9% | Jun 26, 2023 | Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the de... |
| CVE-2023-1619 | MEDIUM | 4.9 | 0.8% | Jun 26, 2023 | Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the de... |
| CVE-2023-1150 | HIGH | 7.5 | 0.7% | Jun 26, 2023 | Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS... |
| CVE-2023-29093 | MEDIUM | 4.8 | 0.4% | Jun 26, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PI Websolution Con... |
| CVE-2023-28992 | MEDIUM | 6.1 | 0.4% | Jun 26, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Elliot Sowersby, RelyWP Coupon Affiliates – WooCommerce Af... |
| CVE-2023-28991 | MEDIUM | 4.8 | 0.4% | Jun 26, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Order date, Order pickup, Order date ti... |
| CVE-2023-28988 | MEDIUM | 4.8 | 0.4% | Jun 26, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Direct checkout, Add to cart redirect, ... |
| CVE-2023-36675 | MEDIUM | 6.1 | 0.7% | Jun 26, 2023 | An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. Bloc... |
| CVE-2023-36662 | MEDIUM | 5.4 | 0.3% | Jun 26, 2023 | The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affe... |
| CVE-2023-36666 | MEDIUM | 6.1 | 0.3% | Jun 25, 2023 | INEX IXP-Manager before 6.3.1 allows XSS. list-preamble.foil.php, page-header-preamble.foil.php, edit-form.foil.php, pag... |
| CVE-2023-36664 | HIGH | 7.8 | 3.4% | Jun 25, 2023 | Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pi... |
| CVE-2023-36661 | HIGH | 7.5 | 2.8% | Jun 25, 2023 | Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyIn... |
| CVE-2023-36660 | CRITICAL | 9.8 | 0.8% | Jun 25, 2023 | The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption. |
| CVE-2023-36663 | HIGH | 8.8 | 0.6% | Jun 25, 2023 | it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the so... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now