2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29163 | HIGH | 7.5 | 0.6% | May 3, 2023 | When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traff... |
| CVE-2023-28742 | HIGH | 8.8 | 1.5% | May 3, 2023 | When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: ... |
| CVE-2023-28724 | HIGH | 7.1 | 0.2% | May 3, 2023 | NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensit... |
| CVE-2023-28656 | HIGH | 8.1 | 0.5% | May 3, 2023 | NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assi... |
| CVE-2023-28406 | MEDIUM | 4.3 | 1.2% | May 3, 2023 | A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an... |
| CVE-2023-27378 | MEDIUM | 6.1 | 0.4% | May 3, 2023 | Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration ut... |
| CVE-2023-24594 | MEDIUM | 5.3 | 0.6% | May 3, 2023 | When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelera... |
| CVE-2023-24461 | MEDIUM | 5.9 | 0.3% | May 3, 2023 | An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow a... |
| CVE-2023-23809 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Moris Dov Stock market charts from finviz plugin <= 1.... |
| CVE-2023-23808 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sergey Panasenko Sponsors Carousel plugin <= 4.02 vers... |
| CVE-2023-23785 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DgCult Exquisite PayPal Donation plugin <= v2.0.0 vers... |
| CVE-2023-22372 | MEDIUM | 5.9 | 0.2% | May 3, 2023 | In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client fo... |
| CVE-2023-25979 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Video Gallery by Total-Soft Video Gallery plugin <= 1.... |
| CVE-2023-23876 | MEDIUM | 5.4 | 0.4% | May 3, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TMS-Plugins wpDataTables plugin <= 2.1.49 versio... |
| CVE-2023-23874 | MEDIUM | 5.4 | 0.4% | May 3, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Metaphor Creations Ditty plugin <= 3.0.32 versio... |
| CVE-2023-22683 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themis Solutions, Inc. Clio Grow plugin <= 1.0.0 versi... |
| CVE-2023-23820 | MEDIUM | 5.4 | 0.4% | May 3, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin... |
| CVE-2023-23708 | MEDIUM | 5.4 | 0.4% | May 3, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager ... |
| CVE-2023-1385 | HIGH | 8.8 | 0.3% | May 3, 2023 | Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known val... |
| CVE-2023-1384 | MEDIUM | 6.1 | 0.4% | May 3, 2023 | The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary ... |
| CVE-2023-25798 | MEDIUM | 5.4 | 0.4% | May 3, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Olevmedia Olevmedia Shortcodes plugin <= 1.1.9 v... |
| CVE-2023-25796 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Include WP BaiDu Submit plugin <= 1.2.1 versions. |
| CVE-2023-22713 | MEDIUM | 5.4 | 0.4% | May 3, 2023 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPres... |
| CVE-2023-1383 | MEDIUM | 4.3 | 0.3% | May 3, 2023 | An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr ser... |
| CVE-2023-25797 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. Stored Cross-Site Scripting (XSS) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now