2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-7293 | MEDIUM | 4.3 | 0.2% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a... |
| CVE-2023-7292 | MEDIUM | 4.3 | 0.3% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal ... |
| CVE-2023-7291 | HIGH | 8.1 | 0.4% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data du... |
| CVE-2023-7290 | MEDIUM | 4.3 | 0.2% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a... |
| CVE-2023-7289 | MEDIUM | 4.3 | 0.3% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a... |
| CVE-2023-7288 | MEDIUM | 4.3 | 0.3% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due t... |
| CVE-2023-7287 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellati... |
| CVE-2023-7286 | MEDIUM | 6.5 | 0.4% | Oct 16, 2024 | The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and ... |
| CVE-2023-31493 | MEDIUM | 6.6 | 0.7% | Oct 15, 2024 | RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in langua... |
| CVE-2023-48082 | CRITICAL | 9.1 | 1.5% | Oct 14, 2024 | Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers... |
| CVE-2023-45817 | — | — | — | Oct 14, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-9823. Reason: This candidate is a r... |
| CVE-2023-50780 | HIGH | 8.8 | 16.5% | Oct 14, 2024 | Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed thro... |
| CVE-2023-42133 | MEDIUM | 6.7 | 0.2% | Oct 11, 2024 | PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must hav... |
| CVE-2023-25581 | CRITICAL | 9.2 | 1.9% | Oct 10, 2024 | pac4j is a security framework for Java. `pac4j-core` prior to version 4.0.0 is affected by a Java deserialization vulner... |
| CVE-2023-46586 | CRITICAL | 9.1 | 0.6% | Oct 9, 2024 | cgi.c in weborf .0.17, 0.18, 0.19, and 0.20 (before 1.0) lacks '\0' termination of the path for CGI scripts because strn... |
| CVE-2023-45872 | MEDIUM | 6.5 | 0.4% | Oct 9, 2024 | An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image wh... |
| CVE-2023-45361 | MEDIUM | 6.1 | 0.3% | Oct 9, 2024 | An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40... |
| CVE-2023-45359 | MEDIUM | 6.5 | 0.3% | Oct 9, 2024 | An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-to... |
| CVE-2023-37154 | HIGH | 8.4 | 0.5% | Oct 9, 2024 | check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and Permi... |
| CVE-2023-36325 | LOW | 3.7 | 0.4% | Oct 9, 2024 | i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) v... |
| CVE-2023-52952 | CRITICAL | 9.3 | 0.2% | Oct 8, 2024 | A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiM... |
| CVE-2023-6362 | HIGH | 7.3 | 0.2% | Oct 7, 2024 | A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buf... |
| CVE-2023-6361 | HIGH | 7.3 | 0.2% | Oct 7, 2024 | A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buf... |
| CVE-2023-26771 | MEDIUM | 6.5 | 0.3% | Oct 4, 2024 | Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading... |
| CVE-2023-26770 | CRITICAL | 9.8 | 0.7% | Oct 4, 2024 | TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can chan... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now