2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6733 | MEDIUM | 6.5 | 0.4% | Jan 4, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2023-6498 | MEDIUM | 4.8 | 0.3% | Jan 4, 2024 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set... |
| CVE-2023-5138 | MEDIUM | 6.8 | 0.3% | Jan 3, 2024 | Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, ex... |
| CVE-2023-5879 | MEDIUM | 6.8 | 0.4% | Jan 3, 2024 | Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Applicat... |
| CVE-2023-6004 | MEDIUM | 4.8 | 0.4% | Jan 3, 2024 | A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syn... |
| CVE-2023-50253 | MEDIUM | 6.5 | 0.7% | Jan 3, 2024 | Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve ... |
| CVE-2023-46742 | MEDIUM | 6.5 | 0.3% | Jan 3, 2024 | CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret ... |
| CVE-2023-46739 | MEDIUM | 5.9 | 0.4% | Jan 3, 2024 | CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master compone... |
| CVE-2023-46738 | MEDIUM | 6.5 | 0.6% | Jan 3, 2024 | CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in v... |
| CVE-2023-30617 | MEDIUM | 6.5 | 0.5% | Jan 3, 2024 | Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to v... |
| CVE-2023-50093 | MEDIUM | 6.1 | 0.4% | Jan 3, 2024 | APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection. |
| CVE-2023-50092 | MEDIUM | 6.1 | 0.4% | Jan 3, 2024 | APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2023-7068 | MEDIUM | 6.5 | 0.4% | Jan 3, 2024 | The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to un... |
| CVE-2023-6984 | MEDIUM | 4.3 | 0.2% | Jan 3, 2024 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-... |
| CVE-2023-6747 | MEDIUM | 5.4 | 0.4% | Jan 3, 2024 | The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2023-6621 | MEDIUM | 6.1 | 0.4% | Jan 3, 2024 | The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in ... |
| CVE-2023-6986 | MEDIUM | 5.4 | 0.4% | Jan 3, 2024 | The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elem... |
| CVE-2023-6981 | MEDIUM | 4.9 | 0.4% | Jan 3, 2024 | The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerab... |
| CVE-2023-6980 | MEDIUM | 4.3 | 0.2% | Jan 3, 2024 | The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerab... |
| CVE-2023-6600 | MEDIUM | 5.4 | 0.5% | Jan 3, 2024 | The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modificat... |
| CVE-2023-6524 | MEDIUM | 5.4 | 0.5% | Jan 3, 2024 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title para... |
| CVE-2023-7027 | MEDIUM | 5.4 | 0.9% | Jan 3, 2024 | The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress i... |
| CVE-2023-6629 | MEDIUM | 6.1 | 0.4% | Jan 3, 2024 | The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress i... |
| CVE-2023-50344 | MEDIUM | 5.4 | 0.3% | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthent... |
| CVE-2023-50343 | MEDIUM | 6.5 | 0.4% | Jan 3, 2024 | HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now