2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-44401 | MEDIUM | 5.3 | 0.4% | Jan 23, 2024 | The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.... |
| CVE-2023-46343 | MEDIUM | 5.5 | 0.2% | Jan 23, 2024 | In the Linux kernel before 6.5.9, there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c. |
| CVE-2023-42937 | MEDIUM | 5.5 | 0.3% | Jan 23, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 an... |
| CVE-2023-42935 | MEDIUM | 5.5 | 0.2% | Jan 23, 2024 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A loc... |
| CVE-2023-42888 | MEDIUM | 5.5 | 0.5% | Jan 23, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS V... |
| CVE-2023-42887 | MEDIUM | 6.3 | 0.2% | Jan 23, 2024 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.6.4, macOS S... |
| CVE-2023-40528 | MEDIUM | 5.5 | 0.2% | Jan 23, 2024 | This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, i... |
| CVE-2023-47141 | MEDIUM | 6.5 | 0.7% | Jan 22, 2024 | IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT p... |
| CVE-2023-7194 | MEDIUM | 6.1 | 0.3% | Jan 22, 2024 | The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the ... |
| CVE-2023-7170 | MEDIUM | 6.1 | 0.4% | Jan 22, 2024 | The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in... |
| CVE-2023-6626 | MEDIUM | 4.8 | 0.4% | Jan 22, 2024 | The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which... |
| CVE-2023-6625 | MEDIUM | 4.3 | 0.2% | Jan 22, 2024 | The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquir... |
| CVE-2023-6456 | MEDIUM | 4.8 | 0.3% | Jan 22, 2024 | The WP Review Slider WordPress plugin before 13.0 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2023-6447 | MEDIUM | 5.3 | 0.6% | Jan 22, 2024 | The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors t... |
| CVE-2023-6384 | MEDIUM | 4.3 | 0.4% | Jan 22, 2024 | The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to ... |
| CVE-2023-6290 | MEDIUM | 4.8 | 0.4% | Jan 22, 2024 | The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privi... |
| CVE-2023-47747 | MEDIUM | 6.5 | 0.7% | Jan 22, 2024 | IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user... |
| CVE-2023-47158 | MEDIUM | 6.5 | 0.7% | Jan 22, 2024 | IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated u... |
| CVE-2023-27859 | MEDIUM | 6.5 | 1.0% | Jan 22, 2024 | IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar fil... |
| CVE-2023-50308 | MEDIUM | 6.5 | 0.8% | Jan 22, 2024 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authen... |
| CVE-2023-47746 | MEDIUM | 6.5 | 0.7% | Jan 22, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user... |
| CVE-2023-44395 | MEDIUM | 6.5 | 0.6% | Jan 22, 2024 | Autolab is a course management service that enables instructors to offer autograded programming assignments to their stu... |
| CVE-2023-7063 | MEDIUM | 6.1 | 0.5% | Jan 20, 2024 | The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all ... |
| CVE-2023-46447 | MEDIUM | 4.3 | 0.4% | Jan 20, 2024 | The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted gluco... |
| CVE-2023-6450 | MEDIUM | 5.5 | 0.2% | Jan 19, 2024 | An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use syst... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now