2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-5931HIGH8.8The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded,...
CVE-2023-5674HIGH8.8The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL...
CVE-2023-5673HIGH8.8The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to em...
CVE-2023-5645HIGH8.8The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL...
CVE-2023-5644HIGH7.6The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with t...
CVE-2023-5203HIGH7.5The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query ...
CVE-2023-52086HIGH8.1resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the files...
CVE-2023-51107HIGH7.5A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_colo...
CVE-2023-51106HIGH7.5A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_ima...
CVE-2023-51105HIGH7.5A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompr...
CVE-2023-51104HIGH7.5A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_...
CVE-2023-51103HIGH7.5A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_...
CVE-2023-49949HIGH8.1Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit...
CVE-2023-50968HIGH7.5Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri cal...
CVE-2023-5180HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used...
CVE-2023-46681HIGH7.8Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ve...
CVE-2023-28616HIGH7.5An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x...
CVE-2023-38321HIGH7.5OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial...
CVE-2023-49226HIGH7.2An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administ...
CVE-2023-36486HIGH7.2The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system comm...
CVE-2023-36485HIGH7.2The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system comm...
CVE-2023-47091HIGH7.5An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through...
CVE-2023-37188HIGH7.5C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_rate_decompress at zfp/b...
CVE-2023-37187HIGH7.5C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the zfp/blosc2-zfp.c zfp_acc_decompress. ...
CVE-2023-37186HIGH7.5C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference in ndlz/ndlz8x8.c via a NULL pointer to memse...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now