2023 CVE Vulnerabilities
31,416 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-30869 | CRITICAL | 9.8 | 3.1% | May 2, 2023 | Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue a... |
| CVE-2023-32007 | HIGH | 8.8 | 75.8% | May 2, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option s... |
| CVE-2023-31207 | MEDIUM | 5.5 | 0.2% | May 2, 2023 | Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause... |
| CVE-2023-2000 | MEDIUM | 5.4 | 0.4% | May 2, 2023 | Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website |
| CVE-2023-1196 | HIGH | 8.8 | 1.1% | May 2, 2023 | The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user ... |
| CVE-2023-1911 | MEDIUM | 4.3 | 0.5% | May 2, 2023 | The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are alrea... |
| CVE-2023-1861 | MEDIUM | 5.4 | 28.8% | May 2, 2023 | The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back... |
| CVE-2023-1809 | HIGH | 7.5 | 0.7% | May 2, 2023 | The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowin... |
| CVE-2023-1805 | MEDIUM | 6.1 | 0.5% | May 2, 2023 | The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the page parameter ... |
| CVE-2023-1804 | MEDIUM | 6.1 | 0.5% | May 2, 2023 | The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter ... |
| CVE-2023-1730 | CRITICAL | 9.8 | 40.6% | May 2, 2023 | The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL stateme... |
| CVE-2023-1669 | HIGH | 7.2 | 18.5% | May 2, 2023 | The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-p... |
| CVE-2023-1614 | MEDIUM | 4.8 | 0.5% | May 2, 2023 | The WP Custom Author URL WordPress plugin before 1.0.5 does not sanitise and escape some of its settings, which could al... |
| CVE-2023-1554 | MEDIUM | 4.8 | 0.5% | May 2, 2023 | The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which coul... |
| CVE-2023-1546 | MEDIUM | 6.1 | 0.9% | May 2, 2023 | The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leadi... |
| CVE-2023-1525 | MEDIUM | 4.8 | 0.5% | May 2, 2023 | The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2023-1125 | MEDIUM | 6.5 | 0.6% | May 2, 2023 | The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user maki... |
| CVE-2023-1090 | MEDIUM | 4.8 | 0.5% | May 2, 2023 | The SMTP Mailing Queue WordPress plugin before 2.0.1 does not sanitise and escape some of its settings, which could allo... |
| CVE-2023-1021 | MEDIUM | 4.8 | 0.4% | May 2, 2023 | The amr ical events lists WordPress plugin through 6.6 does not sanitise and escape some of its settings, which could al... |
| CVE-2023-0924 | HIGH | 7.2 | 1.0% | May 2, 2023 | The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowin... |
| CVE-2023-0891 | MEDIUM | 5.4 | 0.4% | May 2, 2023 | The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2023-21666 | HIGH | 7.8 | 0.2% | May 2, 2023 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. |
| CVE-2023-21665 | HIGH | 7.8 | 0.2% | May 2, 2023 | Memory corruption in Graphics while importing a file. |
| CVE-2023-21642 | HIGH | 7.8 | 0.1% | May 2, 2023 | Memory corruption in HAB Memory management due to broad system privileges via physical address. |
| CVE-2023-2247 | MEDIUM | 5.3 | 0.4% | May 2, 2023 | In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now