2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1124 | HIGH | 7.2 | 1.1% | Apr 3, 2023 | The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticate... |
| CVE-2023-0820 | HIGH | 8.8 | 0.4% | Apr 3, 2023 | The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capa... |
| CVE-2023-0399 | MEDIUM | 5.4 | 0.5% | Apr 3, 2023 | The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shor... |
| CVE-2023-28625 | HIGH | 7.5 | 1.3% | Apr 3, 2023 | mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID... |
| CVE-2023-1766 | MEDIUM | 6.1 | 0.4% | Apr 3, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akbim Computer Pan... |
| CVE-2023-1765 | CRITICAL | 9.8 | 0.7% | Apr 3, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akbim Computer Pan... |
| CVE-2023-26529 | MEDIUM | 4.8 | 0.4% | Apr 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DupeOff.Com DupeOff plugin <= 1.6 versions. |
| CVE-2023-26269 | HIGH | 7.8 | 0.7% | Apr 3, 2023 | Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This ... |
| CVE-2023-26119 | CRITICAL | 9.8 | 2.5% | Apr 3, 2023 | Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Executio... |
| CVE-2023-26112 | MEDIUM | 5.9 | 1.3% | Apr 3, 2023 | All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate fu... |
| CVE-2023-29042 | — | — | — | Apr 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-29041 | — | — | — | Apr 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-29040 | — | — | — | Apr 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-29039 | — | — | — | Apr 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-29038 | — | — | — | Apr 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-29037 | — | — | — | Apr 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-29036 | — | — | — | Apr 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-29035 | — | — | — | Apr 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-29034 | — | — | — | Apr 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-29033 | — | — | — | Apr 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-28684 | MEDIUM | 6.5 | 0.7% | Apr 2, 2023 | Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entit... |
| CVE-2023-28683 | HIGH | 8.2 | 0.6% | Apr 2, 2023 | Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external enti... |
| CVE-2023-28682 | HIGH | 8.2 | 0.6% | Apr 2, 2023 | Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (... |
| CVE-2023-28681 | HIGH | 8.2 | 0.6% | Apr 2, 2023 | Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external enti... |
| CVE-2023-28680 | HIGH | 7.5 | 0.8% | Apr 2, 2023 | Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now