2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27980 | HIGH | 8.8 | 0.9% | Mar 21, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could... |
| CVE-2023-1543 | HIGH | 8.8 | 0.8% | Mar 21, 2023 | Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-1542 | MEDIUM | 5.4 | 0.8% | Mar 21, 2023 | Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-1541 | LOW | 3.8 | 0.6% | Mar 21, 2023 | Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-1540 | MEDIUM | 5.3 | 0.6% | Mar 21, 2023 | Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-1539 | MEDIUM | 5.3 | 0.6% | Mar 21, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-1538 | MEDIUM | 5.3 | 0.6% | Mar 21, 2023 | Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-1537 | CRITICAL | 9.8 | 0.8% | Mar 21, 2023 | Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-1536 | MEDIUM | 5.4 | 0.5% | Mar 21, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7. |
| CVE-2023-1535 | MEDIUM | 5.4 | 0.5% | Mar 21, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7. |
| CVE-2023-1527 | MEDIUM | 5.4 | 0.5% | Mar 21, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0. |
| CVE-2023-28425 | MEDIUM | 5.5 | 55.0% | Mar 20, 2023 | Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticat... |
| CVE-2023-27578 | HIGH | 7.5 | 0.8% | Mar 20, 2023 | Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05... |
| CVE-2023-0681 | MEDIUM | 6.1 | 0.3% | Mar 20, 2023 | Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the abi... |
| CVE-2023-27586 | HIGH | 7.1 | 0.7% | Mar 20, 2023 | CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to e... |
| CVE-2023-22288 | MEDIUM | 5.4 | 0.4% | Mar 20, 2023 | HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticate... |
| CVE-2023-1517 | MEDIUM | 4.8 | 0.4% | Mar 20, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.19. |
| CVE-2023-0940 | HIGH | 8.8 | 0.8% | Mar 20, 2023 | The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not imple... |
| CVE-2023-0937 | MEDIUM | 6.1 | 0.5% | Mar 20, 2023 | The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter ... |
| CVE-2023-0911 | MEDIUM | 6.5 | 0.7% | Mar 20, 2023 | The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to ... |
| CVE-2023-0890 | MEDIUM | 6.5 | 0.7% | Mar 20, 2023 | The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be di... |
| CVE-2023-0876 | MEDIUM | 6.1 | 0.7% | Mar 20, 2023 | The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to m... |
| CVE-2023-0875 | HIGH | 8.8 | 0.9% | Mar 20, 2023 | The WP Meta SEO WordPress plugin before 4.5.3 does not properly sanitize and escape inputs into SQL queries, leading to ... |
| CVE-2023-0865 | HIGH | 8.8 | 1.2% | Mar 20, 2023 | The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to ... |
| CVE-2023-0631 | HIGH | 8.8 | 60.5% | Mar 20, 2023 | The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that conc... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now