2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-7293MEDIUM4.3The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a...
CVE-2023-7292MEDIUM4.3The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal ...
CVE-2023-7291HIGH8.1The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data du...
CVE-2023-7290MEDIUM4.3The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a...
CVE-2023-7289MEDIUM4.3The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a...
CVE-2023-7288MEDIUM4.3The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due t...
CVE-2023-7287MEDIUM5.4The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellati...
CVE-2023-7286MEDIUM6.5The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and ...
CVE-2023-31493MEDIUM6.6RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in langua...
CVE-2023-48082CRITICAL9.1Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers...
CVE-2023-45817Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-9823. Reason: This candidate is a r...
CVE-2023-50780HIGH8.8Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed thro...
CVE-2023-42133MEDIUM6.7PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must hav...
CVE-2023-25581CRITICAL9.2pac4j is a security framework for Java. `pac4j-core` prior to version 4.0.0 is affected by a Java deserialization vulner...
CVE-2023-46586CRITICAL9.1cgi.c in weborf .0.17, 0.18, 0.19, and 0.20 (before 1.0) lacks '\0' termination of the path for CGI scripts because strn...
CVE-2023-45872MEDIUM6.5An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image wh...
CVE-2023-45361MEDIUM6.1An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40...
CVE-2023-45359MEDIUM6.5An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-to...
CVE-2023-37154HIGH8.4check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and Permi...
CVE-2023-36325LOW3.7i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) v...
CVE-2023-52952CRITICAL9.3A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiM...
CVE-2023-6362HIGH7.3A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buf...
CVE-2023-6361HIGH7.3A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buf...
CVE-2023-26771MEDIUM6.5Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading...
CVE-2023-26770CRITICAL9.8TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can chan...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now