2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-44401MEDIUM5.3The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3....
CVE-2023-46343MEDIUM5.5In the Linux kernel before 6.5.9, there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c.
CVE-2023-42937MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 an...
CVE-2023-42935MEDIUM5.5An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A loc...
CVE-2023-42888MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS V...
CVE-2023-42887MEDIUM6.3An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.6.4, macOS S...
CVE-2023-40528MEDIUM5.5This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, i...
CVE-2023-47141MEDIUM6.5IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT p...
CVE-2023-7194MEDIUM6.1The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the ...
CVE-2023-7170MEDIUM6.1The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in...
CVE-2023-6626MEDIUM4.8The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which...
CVE-2023-6625MEDIUM4.3The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquir...
CVE-2023-6456MEDIUM4.8The WP Review Slider WordPress plugin before 13.0 does not sanitise and escape some of its settings, which could allow h...
CVE-2023-6447MEDIUM5.3The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors t...
CVE-2023-6384MEDIUM4.3The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to ...
CVE-2023-6290MEDIUM4.8The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privi...
CVE-2023-47747MEDIUM6.5IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user...
CVE-2023-47158MEDIUM6.5IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated u...
CVE-2023-27859MEDIUM6.5IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar fil...
CVE-2023-50308MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authen...
CVE-2023-47746MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user...
CVE-2023-44395MEDIUM6.5Autolab is a course management service that enables instructors to offer autograded programming assignments to their stu...
CVE-2023-7063MEDIUM6.1The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all ...
CVE-2023-46447MEDIUM4.3The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted gluco...
CVE-2023-6450MEDIUM5.5An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use syst...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now