2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1124HIGH7.2The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticate...
CVE-2023-0820HIGH8.8The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capa...
CVE-2023-0399MEDIUM5.4The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shor...
CVE-2023-28625HIGH7.5mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID...
CVE-2023-1766MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akbim Computer Pan...
CVE-2023-1765CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akbim Computer Pan...
CVE-2023-26529MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DupeOff.Com DupeOff plugin <= 1.6 versions.
CVE-2023-26269HIGH7.8Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This ...
CVE-2023-26119CRITICAL9.8Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Executio...
CVE-2023-26112MEDIUM5.9All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate fu...
CVE-2023-29042Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-29041Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-29040Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-29039Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-29038Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-29037Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-29036Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-29035Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-29034Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-29033Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-28684MEDIUM6.5Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entit...
CVE-2023-28683HIGH8.2Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external enti...
CVE-2023-28682HIGH8.2Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (...
CVE-2023-28681HIGH8.2Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external enti...
CVE-2023-28680HIGH7.5Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now