2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48865 | MEDIUM | 6.5 | 0.6% | Apr 11, 2024 | An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter ... |
| CVE-2023-5394 | HIGH | 7.4 | 0.7% | Apr 11, 2024 | Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overfl... |
| CVE-2023-5393 | HIGH | 7.4 | 0.7% | Apr 11, 2024 | Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in po... |
| CVE-2023-5392 | HIGH | 7.5 | 0.5% | Apr 11, 2024 | C300 information leak due to an analysis feature which allows extracting more memory over the network than required by t... |
| CVE-2023-50949 | HIGH | 8.1 | 0.3% | Apr 11, 2024 | IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validat... |
| CVE-2023-29483 | HIGH | 7 | 1.9% | Apr 11, 2024 | eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution... |
| CVE-2023-32295 | MEDIUM | 6.3 | 0.4% | Apr 11, 2024 | Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a ... |
| CVE-2023-32228 | MEDIUM | 4.6 | 0.2% | Apr 11, 2024 | A firmware bug which may lead to misinterpretation of data in the AMC2-4WCF and AMC2-2WCF allowing an adversary to grant... |
| CVE-2023-6257 | MEDIUM | 4.3 | 0.4% | Apr 11, 2024 | The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users a... |
| CVE-2023-6811 | HIGH | 7.2 | 0.4% | Apr 11, 2024 | The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2023-51672 | HIGH | 7.5 | 0.5% | Apr 11, 2024 | Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a thro... |
| CVE-2023-51142 | HIGH | 7.5 | 0.9% | Apr 11, 2024 | An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information. |
| CVE-2023-51141 | MEDIUM | 6.5 | 0.8% | Apr 11, 2024 | An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentic... |
| CVE-2023-27607 | MEDIUM | 5.4 | 0.4% | Apr 11, 2024 | Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Reward... |
| CVE-2023-52070 | HIGH | 8.4 | 0.3% | Apr 10, 2024 | JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)... |
| CVE-2023-6916 | HIGH | 7.5 | 0.6% | Apr 10, 2024 | Audit records for OpenAPI requests may include sensitive information. This could lead to unauthorized accesses and pr... |
| CVE-2023-2794 | HIGH | 8.1 | 1.2% | Apr 10, 2024 | A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_delive... |
| CVE-2023-6385 | MEDIUM | 4.3 | 0.2% | Apr 10, 2024 | The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could a... |
| CVE-2023-50347 | CRITICAL | 9.8 | 0.6% | Apr 10, 2024 | HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability... |
| CVE-2023-6236 | HIGH | 7.3 | 0.3% | Apr 10, 2024 | A flaw was found in Red Hat Enterprise Application Platform 8. When an OIDC app that serves multiple tenants attempts to... |
| CVE-2023-40148 | MEDIUM | 6.5 | 0.5% | Apr 10, 2024 | Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and ... |
| CVE-2023-7046 | HIGH | 7.5 | 0.4% | Apr 9, 2024 | The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPress... |
| CVE-2023-6999 | HIGH | 8.8 | 1.3% | Apr 9, 2024 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in... |
| CVE-2023-6993 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Custom post types, Custom Fields & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2023-6967 | HIGH | 8.8 | 0.8% | Apr 9, 2024 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all vers... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now