2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36520 | HIGH | 8.1 | 0.4% | Dec 20, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in MarketingFire Editorial Calendar.This issue affects Ed... |
| CVE-2023-35876 | HIGH | 8.1 | 0.6% | Dec 20, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooC... |
| CVE-2023-32590 | HIGH | 7.5 | 1.6% | Dec 20, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström ... |
| CVE-2023-50249 | HIGH | 7.5 | 0.8% | Dec 20, 2023 | Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Regular expression Denial of Service) vulnerability h... |
| CVE-2023-46147 | HIGH | 8.8 | 0.5% | Dec 20, 2023 | Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a thro... |
| CVE-2023-37871 | HIGH | 7.5 | 0.5% | Dec 20, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: ... |
| CVE-2023-6562 | HIGH | 7.5 | 0.7% | Dec 20, 2023 | JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachab... |
| CVE-2023-37544 | HIGH | 7.5 | 1.4% | Dec 20, 2023 | Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong en... |
| CVE-2023-6977 | HIGH | 7.5 | 3.9% | Dec 20, 2023 | This vulnerability enables malicious users to read sensitive files on the server. |
| CVE-2023-6976 | HIGH | 8.8 | 1.0% | Dec 20, 2023 | This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the contex... |
| CVE-2023-47706 | HIGH | 8.8 | 0.8% | Dec 20, 2023 | IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file ty... |
| CVE-2023-47704 | HIGH | 7.5 | 0.6% | Dec 20, 2023 | IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source co... |
| CVE-2023-6689 | HIGH | 8.8 | 0.3% | Dec 20, 2023 | A successful CSRF attack could force the user to perform state changing requests on the application. If the victim ... |
| CVE-2023-50707 | HIGH | 7.5 | 0.7% | Dec 20, 2023 | Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service c... |
| CVE-2023-49147 | HIGH | 7.8 | 0.5% | Dec 19, 2023 | An issue was discovered in PDF24 Creator 11.14.0. The configuration of the msi installer file was found to produce a vis... |
| CVE-2023-50835 | HIGH | 8.8 | 0.3% | Dec 19, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Praveen Goswami Advanced Category Template.This issue affects Advance... |
| CVE-2023-49164 | HIGH | 8.8 | 0.3% | Dec 19, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through ... |
| CVE-2023-38126 | HIGH | 7.2 | 68.6% | Dec 19, 2023 | Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability... |
| CVE-2023-50466 | HIGH | 8.8 | 1.9% | Dec 19, 2023 | An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows att... |
| CVE-2023-49812 | HIGH | 7.5 | 0.5% | Dec 19, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This... |
| CVE-2023-49764 | HIGH | 7.2 | 0.7% | Dec 19, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Younes JFR. Advanc... |
| CVE-2023-48764 | HIGH | 7.2 | 0.7% | Dec 19, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GuardGiant Brute F... |
| CVE-2023-48741 | HIGH | 7.2 | 0.7% | Dec 19, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud AI Ch... |
| CVE-2023-48327 | HIGH | 7.2 | 0.7% | Dec 19, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Vendors WC Vend... |
| CVE-2023-43826 | HIGH | 8.8 | 0.9% | Dec 19, 2023 | Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in in... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now