2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31002 | MEDIUM | 5.5 | 0.1% | Feb 7, 2024 | IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that c... |
| CVE-2023-39196 | MEDIUM | 5.3 | 0.8% | Feb 7, 2024 | Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata intern... |
| CVE-2023-40355 | MEDIUM | 5.4 | 1.1% | Feb 7, 2024 | Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0... |
| CVE-2023-6388 | MEDIUM | 5 | 0.5% | Feb 7, 2024 | Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because ... |
| CVE-2023-45227 | MEDIUM | 5.4 | 0.3% | Feb 6, 2024 | An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScr... |
| CVE-2023-45222 | MEDIUM | 5.4 | 0.3% | Feb 6, 2024 | An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript ... |
| CVE-2023-45213 | MEDIUM | 6.5 | 0.4% | Feb 6, 2024 | A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could a... |
| CVE-2023-42765 | MEDIUM | 5.4 | 0.3% | Feb 6, 2024 | An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-si... |
| CVE-2023-40544 | MEDIUM | 5.7 | 0.2% | Feb 6, 2024 | An attacker with access to the network where the affected devices are located could maliciously actions to ob... |
| CVE-2023-40143 | MEDIUM | 5.4 | 0.3% | Feb 6, 2024 | An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary... |
| CVE-2023-46183 | MEDIUM | 4.4 | 0.2% | Feb 6, 2024 | IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could all... |
| CVE-2023-32474 | MEDIUM | 6.6 | 0.2% | Feb 6, 2024 | Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount p... |
| CVE-2023-28063 | MEDIUM | 4.4 | 0.2% | Feb 6, 2024 | Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin... |
| CVE-2023-52239 | MEDIUM | 6.5 | 0.4% | Feb 6, 2024 | The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport. |
| CVE-2023-33064 | MEDIUM | 5.5 | 0.1% | Feb 6, 2024 | Transient DOS in Audio when invoking callback function of ASM driver. |
| CVE-2023-33060 | MEDIUM | 5.5 | 0.1% | Feb 6, 2024 | Transient DOS in Core when DDR memory check is called while DDR is not initialized. |
| CVE-2023-47022 | MEDIUM | 6.5 | 0.3% | Feb 6, 2024 | Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for ... |
| CVE-2023-7029 | MEDIUM | 5.4 | 0.4% | Feb 5, 2024 | The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2023-6983 | MEDIUM | 4.3 | 0.5% | Feb 5, 2024 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure ... |
| CVE-2023-6982 | MEDIUM | 5.4 | 0.4% | Feb 5, 2024 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2023-6963 | MEDIUM | 5.3 | 0.5% | Feb 5, 2024 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0... |
| CVE-2023-6959 | MEDIUM | 4.3 | 0.4% | Feb 5, 2024 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2023-6953 | MEDIUM | 5.4 | 0.4% | Feb 5, 2024 | The PDF Generator For Fluent Forms – The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
| CVE-2023-6884 | MEDIUM | 5.4 | 0.6% | Feb 5, 2024 | This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to,... |
| CVE-2023-6808 | MEDIUM | 5.4 | 0.5% | Feb 5, 2024 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Script... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now