2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48865MEDIUM6.5An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter ...
CVE-2023-5394HIGH7.4Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overfl...
CVE-2023-5393HIGH7.4Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in po...
CVE-2023-5392HIGH7.5C300 information leak due to an analysis feature which allows extracting more memory over the network than required by t...
CVE-2023-50949HIGH8.1IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validat...
CVE-2023-29483HIGH7eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution...
CVE-2023-32295MEDIUM6.3Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a ...
CVE-2023-32228MEDIUM4.6A firmware bug which may lead to misinterpretation of data in the AMC2-4WCF and AMC2-2WCF allowing an adversary to grant...
CVE-2023-6257MEDIUM4.3The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users a...
CVE-2023-6811HIGH7.2The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2023-51672HIGH7.5Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a thro...
CVE-2023-51142HIGH7.5An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information.
CVE-2023-51141MEDIUM6.5An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentic...
CVE-2023-27607MEDIUM5.4Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Reward...
CVE-2023-52070HIGH8.4JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)...
CVE-2023-6916HIGH7.5Audit records for OpenAPI requests may include sensitive information. This could lead to unauthorized accesses and pr...
CVE-2023-2794HIGH8.1A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_delive...
CVE-2023-6385MEDIUM4.3The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could a...
CVE-2023-50347CRITICAL9.8HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability...
CVE-2023-6236HIGH7.3A flaw was found in Red Hat Enterprise Application Platform 8. When an OIDC app that serves multiple tenants attempts to...
CVE-2023-40148MEDIUM6.5Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and ...
CVE-2023-7046HIGH7.5The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress...
CVE-2023-6999HIGH8.8The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in...
CVE-2023-6993MEDIUM6.4The Custom post types, Custom Fields & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2023-6967HIGH8.8The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all vers...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now