2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1410 | MEDIUM | 4.8 | 1.0% | Mar 23, 2023 | Grafana is an open-source platform for monitoring and observability. Grafana had a stored XSS vulnerability in the Gra... |
| CVE-2023-1051 | MEDIUM | 6.1 | 0.4% | Mar 23, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in As Koc Energy Web ... |
| CVE-2023-1050 | CRITICAL | 9.8 | 0.6% | Mar 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web ... |
| CVE-2023-26114 | CRITICAL | 9.3 | 0.3% | Mar 23, 2023 | Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. ... |
| CVE-2023-28759 | HIGH | 7.8 | 0.2% | Mar 23, 2023 | An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the... |
| CVE-2023-28758 | HIGH | 7.1 | 0.2% | Mar 23, 2023 | An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path... |
| CVE-2023-27249 | MEDIUM | 5.5 | 0.4% | Mar 23, 2023 | swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c. |
| CVE-2023-26496 | CRITICAL | 9.8 | 24.1% | Mar 23, 2023 | An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1... |
| CVE-2023-24367 | — | — | — | Mar 23, 2023 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2023-23192 | HIGH | 7.2 | 1.5% | Mar 23, 2023 | IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task. |
| CVE-2023-28470 | MEDIUM | 5.3 | 0.6% | Mar 23, 2023 | In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication. |
| CVE-2023-26498 | CRITICAL | 9.8 | 24.1% | Mar 23, 2023 | An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1... |
| CVE-2023-26088 | HIGH | 7.8 | 0.5% | Mar 23, 2023 | In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the loc... |
| CVE-2023-24655 | CRITICAL | 9.8 | 1.0% | Mar 23, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name... |
| CVE-2023-27100 | CRITICAL | 9.8 | 9.8% | Mar 22, 2023 | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22... |
| CVE-2023-27060 | CRITICAL | 9.8 | 1.3% | Mar 22, 2023 | LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function. |
| CVE-2023-27054 | MEDIUM | 6.1 | 0.6% | Mar 22, 2023 | A cross-site scripting (XSS) vulnerability in MiroTalk P2P before commit f535b35 allows attackers to execute arbitrary w... |
| CVE-2023-28667 | CRITICAL | 9.8 | 1.1% | Mar 22, 2023 | The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue.... |
| CVE-2023-28666 | MEDIUM | 5.4 | 0.4% | Mar 22, 2023 | The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability ... |
| CVE-2023-28665 | MEDIUM | 5.4 | 0.9% | Mar 22, 2023 | The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnera... |
| CVE-2023-28664 | MEDIUM | 5.4 | 0.4% | Mar 22, 2023 | The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripti... |
| CVE-2023-28663 | HIGH | 8.8 | 0.9% | Mar 22, 2023 | The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in ... |
| CVE-2023-28662 | CRITICAL | 9.8 | 42.2% | Mar 22, 2023 | The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL in... |
| CVE-2023-28661 | HIGH | 8.8 | 0.9% | Mar 22, 2023 | The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in ... |
| CVE-2023-28660 | HIGH | 8.8 | 0.9% | Mar 22, 2023 | The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now