2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1122 | MEDIUM | 4.8 | 0.4% | Apr 10, 2023 | The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its Giveaways options, which co... |
| CVE-2023-1121 | MEDIUM | 4.8 | 0.4% | Apr 10, 2023 | The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow... |
| CVE-2023-1120 | MEDIUM | 4.8 | 0.4% | Apr 10, 2023 | The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow... |
| CVE-2023-0983 | MEDIUM | 6.1 | 0.5% | Apr 10, 2023 | The stylish-cost-calculator-premium WordPress plugin before 7.9.0 does not sanitise and escape a parameter before output... |
| CVE-2023-0893 | MEDIUM | 4.8 | 0.4% | Apr 10, 2023 | The Time Sheets WordPress plugin before 1.29.3 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2023-0874 | MEDIUM | 4.8 | 0.4% | Apr 10, 2023 | The Klaviyo WordPress plugin before 3.0.10 does not sanitize and escape some of its settings, which could allow high-pri... |
| CVE-2023-0605 | MEDIUM | 4.8 | 0.5% | Apr 10, 2023 | The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which c... |
| CVE-2023-0546 | MEDIUM | 5.4 | 0.5% | Apr 10, 2023 | The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in ifr... |
| CVE-2023-0423 | MEDIUM | 4.8 | 0.4% | Apr 10, 2023 | The WordPress Amazon S3 Plugin WordPress plugin before 1.6 does not sanitise and escape a parameter before outputting it... |
| CVE-2023-0422 | MEDIUM | 4.8 | 0.5% | Apr 10, 2023 | The Article Directory WordPress plugin through 1.3 does not properly sanitize the `publish_terms_text` setting before di... |
| CVE-2023-0363 | MEDIUM | 5.4 | 0.4% | Apr 10, 2023 | The Scheduled Announcements Widget WordPress plugin before 1.0 does not validate and escape some of its shortcode attrib... |
| CVE-2023-0157 | MEDIUM | 4.8 | 32.5% | Apr 10, 2023 | The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting ... |
| CVE-2023-0156 | MEDIUM | 4.9 | 19.9% | Apr 10, 2023 | The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings p... |
| CVE-2023-26860 | HIGH | 8.8 | 1.1% | Apr 10, 2023 | SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges v... |
| CVE-2023-26788 | MEDIUM | 6.1 | 0.4% | Apr 10, 2023 | Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause t... |
| CVE-2023-26774 | HIGH | 7.5 | 1.4% | Apr 10, 2023 | An issue found in Sales Tracker Management System v.1.0 allows a remote attacker to access sensitive information via sal... |
| CVE-2023-29216 | CRITICAL | 9.8 | 2.1% | Apr 10, 2023 | In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source a... |
| CVE-2023-29215 | CRITICAL | 9.8 | 2.1% | Apr 10, 2023 | In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql ... |
| CVE-2023-27987 | CRITICAL | 9.1 | 0.8% | Apr 10, 2023 | In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy ... |
| CVE-2023-27603 | CRITICAL | 9.8 | 1.8% | Apr 10, 2023 | In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a... |
| CVE-2023-27602 | CRITICAL | 9.8 | 2.0% | Apr 10, 2023 | In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files,... |
| CVE-2023-26120 | MEDIUM | 6.1 | 0.5% | Apr 10, 2023 | This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-j... |
| CVE-2023-30456 | MEDIUM | 6.5 | 0.5% | Apr 10, 2023 | An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency ... |
| CVE-2023-27720 | CRITICAL | 9.8 | 1.4% | Apr 9, 2023 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows a... |
| CVE-2023-27719 | CRITICAL | 9.8 | 1.4% | Apr 9, 2023 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now