2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-49734 | MEDIUM | 6.5 | 0.9% | Dec 19, 2023 | An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically be... |
| CVE-2023-49489 | MEDIUM | 6.1 | 0.7% | Dec 19, 2023 | Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive in... |
| CVE-2023-49006 | MEDIUM | 6.5 | 0.5% | Dec 19, 2023 | Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive... |
| CVE-2023-46104 | MEDIUM | 6.5 | 1.7% | Dec 19, 2023 | Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import data... |
| CVE-2023-50376 | MEDIUM | 6.1 | 0.5% | Dec 19, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smp7, wp.Insider S... |
| CVE-2023-5432 | MEDIUM | 5.4 | 0.4% | Dec 19, 2023 | The Jquery news ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jquery-news-ticker' shortc... |
| CVE-2023-5413 | MEDIUM | 5.4 | 0.4% | Dec 19, 2023 | The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ihrss-... |
| CVE-2023-42015 | MEDIUM | 4.3 | 0.6% | Dec 19, 2023 | IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vulnerable to HTML inje... |
| CVE-2023-6488 | MEDIUM | 5.4 | 0.5% | Dec 19, 2023 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2023-6918 | MEDIUM | 5.3 | 1.4% | Dec 19, 2023 | A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different sup... |
| CVE-2023-6927 | MEDIUM | 6.1 | 1.1% | Dec 18, 2023 | A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using... |
| CVE-2023-47558 | MEDIUM | 6.5 | 0.7% | Dec 18, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mahlamusa Who Hit ... |
| CVE-2023-6355 | MEDIUM | 6.8 | 0.4% | Dec 18, 2023 | Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechani... |
| CVE-2023-41967 | MEDIUM | 4.6 | 0.3% | Dec 18, 2023 | Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacke... |
| CVE-2023-23584 | MEDIUM | 4.3 | 0.5% | Dec 18, 2023 | An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to ... |
| CVE-2023-23576 | MEDIUM | 4.3 | 0.3% | Dec 18, 2023 | Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site ... |
| CVE-2023-22439 | MEDIUM | 4.3 | 0.5% | Dec 18, 2023 | Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web in... |
| CVE-2023-40691 | MEDIUM | 4.9 | 0.7% | Dec 18, 2023 | IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21... |
| CVE-2023-6289 | MEDIUM | 4.3 | 0.9% | Dec 18, 2023 | The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings,... |
| CVE-2023-6077 | MEDIUM | 6.5 | 0.7% | Dec 18, 2023 | The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and ca... |
| CVE-2023-6065 | MEDIUM | 5.3 | 18.7% | Dec 18, 2023 | The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which all... |
| CVE-2023-5348 | MEDIUM | 6.1 | 0.5% | Dec 18, 2023 | The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or e... |
| CVE-2023-5005 | MEDIUM | 4.8 | 0.4% | Dec 18, 2023 | The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-p... |
| CVE-2023-47741 | MEDIUM | 5.3 | 0.3% | Dec 18, 2023 | IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser m... |
| CVE-2023-51385 | MEDIUM | 6.5 | 19.8% | Dec 18, 2023 | In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now