2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0778 | MEDIUM | 6.8 | 0.5% | Mar 27, 2023 | A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal... |
| CVE-2023-0494 | HIGH | 7.8 | 0.9% | Mar 27, 2023 | A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be ex... |
| CVE-2023-0241 | MEDIUM | 6.5 | 8.8% | Mar 27, 2023 | pgAdmin 4 versions prior to v6.19 contains a directory traversal vulnerability. A user of the product may change another... |
| CVE-2023-28655 | MEDIUM | 5.4 | 0.3% | Mar 27, 2023 | A malicious user could leverage this vulnerability to escalate privileges or perform unauthorized actions in the context... |
| CVE-2023-28652 | MEDIUM | 6.5 | 0.6% | Mar 27, 2023 | An authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition. |
| CVE-2023-28650 | MEDIUM | 6.1 | 0.5% | Mar 27, 2023 | An unauthenticated remote attacker could provide a malicious link and trick an unsuspecting user into clicking on it. If... |
| CVE-2023-27927 | MEDIUM | 6.5 | 0.4% | Mar 27, 2023 | An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, des... |
| CVE-2023-25818 | HIGH | 7.1 | 0.6% | Mar 27, 2023 | Nextcloud server is an open source, personal cloud implementation. In affected versions a malicious user could try to re... |
| CVE-2023-25661 | MEDIUM | 6.5 | 0.4% | Mar 27, 2023 | TensorFlow is an Open Source Machine Learning Framework. In versions prior to 2.11.1 a malicious invalid input crashes a... |
| CVE-2023-22300 | MEDIUM | 6.1 | 0.5% | Mar 27, 2023 | An unauthenticated remote attacker could force all authenticated users, such as administrative users, to perform unautho... |
| CVE-2023-27245 | MEDIUM | 6.1 | 0.4% | Mar 27, 2023 | A cross-site scripting (XSS) vulnerability in File Management Project 1.0.0 allows attackers to execute arbitrary web sc... |
| CVE-2023-27241 | MEDIUM | 6.1 | 0.4% | Mar 27, 2023 | SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the la... |
| CVE-2023-25828 | HIGH | 7.2 | 1.6% | Mar 27, 2023 | Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albu... |
| CVE-2023-27847 | CRITICAL | 9.8 | 4.7% | Mar 27, 2023 | SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges vi... |
| CVE-2023-1654 | HIGH | 7.8 | 0.3% | Mar 27, 2023 | Denial of Service in GitHub repository gpac/gpac prior to 2.4.0. |
| CVE-2023-1400 | MEDIUM | 4.8 | 0.5% | Mar 27, 2023 | The Modern Events Calendar Lite WordPress plugin before 6.5.2 does not sanitise and escape some of its settings, which c... |
| CVE-2023-1399 | CRITICAL | 9.8 | 0.8% | Mar 27, 2023 | N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious ... |
| CVE-2023-1093 | MEDIUM | 6.5 | 0.3% | Mar 27, 2023 | The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (Id... |
| CVE-2023-1092 | MEDIUM | 6.5 | 0.4% | Mar 27, 2023 | The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4... |
| CVE-2023-1089 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The Coupon Zen WordPress plugin before 1.0.6 does not have CSRF check when activating plugins, which could allow attacke... |
| CVE-2023-1088 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The WP Plugin Manager WordPress plugin before 1.1.8 does not have CSRF check when activating plugins, which could allow ... |
| CVE-2023-1087 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could al... |
| CVE-2023-1086 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The Preview Link Generator WordPress plugin before 1.0.4 does not have CSRF check when activating plugins, which could a... |
| CVE-2023-1069 | MEDIUM | 5.4 | 0.6% | Mar 27, 2023 | The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape ... |
| CVE-2023-1025 | MEDIUM | 4.8 | 0.4% | Mar 27, 2023 | The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now