2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6807 | MEDIUM | 5.4 | 0.4% | Feb 5, 2024 | The GeneratePress Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom meta... |
| CVE-2023-6701 | MEDIUM | 5.4 | 0.5% | Feb 5, 2024 | The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text fie... |
| CVE-2023-6557 | MEDIUM | 5.3 | 0.6% | Feb 5, 2024 | The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ... |
| CVE-2023-6526 | MEDIUM | 5.4 | 0.4% | Feb 5, 2024 | The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via c... |
| CVE-2023-4637 | MEDIUM | 5.3 | 0.6% | Feb 5, 2024 | The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the r... |
| CVE-2023-34042 | MEDIUM | 5.5 | 0.2% | Feb 5, 2024 | The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extra... |
| CVE-2023-22819 | MEDIUM | 4.9 | 0.8% | Feb 5, 2024 | An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to co... |
| CVE-2023-22817 | MEDIUM | 5.5 | 0.2% | Feb 5, 2024 | Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL ... |
| CVE-2023-6028 | MEDIUM | 6.1 | 0.4% | Feb 5, 2024 | A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Auto... |
| CVE-2023-7216 | MEDIUM | 5.3 | 0.9% | Feb 5, 2024 | A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker t... |
| CVE-2023-51504 | MEDIUM | 5.4 | 0.7% | Feb 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's ... |
| CVE-2023-52426 | MEDIUM | 5.5 | 0.4% | Feb 4, 2024 | libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time. |
| CVE-2023-6240 | MEDIUM | 6.5 | 1.0% | Feb 4, 2024 | A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue ma... |
| CVE-2023-50947 | MEDIUM | 5.4 | 0.4% | Feb 4, 2024 | IBM Business Automation Workflow 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability al... |
| CVE-2023-33851 | MEDIUM | 4.9 | 0.4% | Feb 4, 2024 | IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could rev... |
| CVE-2023-49950 | MEDIUM | 5.4 | 0.5% | Feb 3, 2024 | The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being display... |
| CVE-2023-37528 | MEDIUM | 6.1 | 0.3% | Feb 3, 2024 | A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an att... |
| CVE-2023-32329 | MEDIUM | 5.5 | 0.2% | Feb 3, 2024 | IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security V... |
| CVE-2023-37527 | MEDIUM | 6.1 | 0.4% | Feb 2, 2024 | A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly al... |
| CVE-2023-50359 | MEDIUM | 6.7 | 0.2% | Feb 2, 2024 | An unchecked return value vulnerability has been reported to affect several QNAP operating system versions. If exploited... |
| CVE-2023-47561 | MEDIUM | 5.4 | 0.3% | Feb 2, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability co... |
| CVE-2023-45028 | MEDIUM | 4.9 | 0.4% | Feb 2, 2024 | An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. I... |
| CVE-2023-45027 | MEDIUM | 4.9 | 0.5% | Feb 2, 2024 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul... |
| CVE-2023-45026 | MEDIUM | 4.9 | 0.5% | Feb 2, 2024 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul... |
| CVE-2023-41274 | MEDIUM | 4.9 | 0.4% | Feb 2, 2024 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploite... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now