2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5505 | MEDIUM | 6.8 | 1.0% | Aug 17, 2024 | The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the j... |
| CVE-2023-52889 | MEDIUM | 5.5 | 0.2% | Aug 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix null pointer deref when receiving skb... |
| CVE-2023-3409 | MEDIUM | 4.3 | 0.2% | Aug 17, 2024 | The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This... |
| CVE-2023-3408 | MEDIUM | 4.3 | 0.2% | Aug 17, 2024 | The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This... |
| CVE-2023-4730 | MEDIUM | 5.3 | 0.5% | Aug 17, 2024 | The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ... |
| CVE-2023-4604 | MEDIUM | 6.1 | 0.3% | Aug 17, 2024 | The Slideshow, Image Slider by 2J plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post’ pa... |
| CVE-2023-4507 | MEDIUM | 6.1 | 0.3% | Aug 17, 2024 | The Admission AppManager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in v... |
| CVE-2023-4027 | MEDIUM | 5.3 | 0.4% | Aug 17, 2024 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2023-4025 | MEDIUM | 5.3 | 0.4% | Aug 17, 2024 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2023-4024 | MEDIUM | 5.3 | 0.4% | Aug 17, 2024 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2023-1604 | MEDIUM | 4.7 | 0.2% | Aug 17, 2024 | The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. ... |
| CVE-2023-4717 | — | — | — | Aug 16, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2023-47728 | MEDIUM | 6.5 | 0.5% | Aug 16, 2024 | IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could al... |
| CVE-2023-3207 | — | — | — | Aug 16, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-31237. Reason: This candidate is a ... |
| CVE-2023-5888 | — | — | — | Aug 16, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-7246. Reason: This candidate is a r... |
| CVE-2023-2920 | — | — | — | Aug 16, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1503. Reason: This candidate is a r... |
| CVE-2023-7049 | MEDIUM | 4.3 | 0.4% | Aug 16, 2024 | The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versio... |
| CVE-2023-37228 | — | — | — | Aug 15, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and... |
| CVE-2023-50314 | HIGH | 7.5 | 0.3% | Aug 14, 2024 | IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to... |
| CVE-2023-50315 | MEDIUM | 5.9 | 0.3% | Aug 14, 2024 | IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing atta... |
| CVE-2023-49144 | HIGH | 8.1 | 0.2% | Aug 14, 2024 | Out of bounds read in OpenBMC Firmware for some Intel(R) Server Platforms before versions egs-1.15-0, bhs-0.27 may allow... |
| CVE-2023-49141 | HIGH | 7.8 | 0.3% | Aug 14, 2024 | Improper isolation in some Intel(R) Processors stream cache mechanism may allow an authenticated user to potentially ena... |
| CVE-2023-48361 | MEDIUM | 4.6 | 0.2% | Aug 14, 2024 | Improper initialization in firmware for some Intel(R) CSME may allow a privileged user to potentially enable information... |
| CVE-2023-43747 | MEDIUM | 6.7 | 0.1% | Aug 14, 2024 | Incorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 ma... |
| CVE-2023-43489 | MEDIUM | 5.5 | 0.1% | Aug 14, 2024 | Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to poten... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now