2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32282HIGH7.2Race condition in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalatio...
CVE-2023-28746MEDIUM6.5Information exposure through microarchitectural state after transient execution from some register files for some Intel(...
CVE-2023-28389MEDIUM6.7Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authentica...
CVE-2023-27502LOW3.3Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2...
CVE-2023-22655MEDIUM6.1Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel...
CVE-2023-50168HIGH7.7Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
CVE-2023-38536MEDIUM6.1HTML injection in OpenText™ Exceed Turbo X affecting version 12.5.1. The vulnerability could result in Cross site script...
CVE-2023-38535CRITICAL9.8Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The ...
CVE-2023-38534HIGH7.5Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerabilit...
CVE-2023-50726MEDIUM6.4Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows...
CVE-2023-41505CRITICAL9.8An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 a...
CVE-2023-41504HIGH8.8SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Sear...
CVE-2023-36238MEDIUM6.5Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the in...
CVE-2023-7015MEDIUM6.1The File Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tb' parameter in all ...
CVE-2023-6969MEDIUM4.3The User Shortcodes Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a...
CVE-2023-6957MEDIUM5.4The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2023-6954MEDIUM5.4The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)...
CVE-2023-6880MEDIUM5.4The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages pl...
CVE-2023-6825CRITICAL9.9The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and...
CVE-2023-6809MEDIUM5.4The Custom fields shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf shortc...
CVE-2023-6785MEDIUM5.3The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in a...
CVE-2023-5663HIGH8.8The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions ...
CVE-2023-52608MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Check mailbox/SMT channel for c...
CVE-2023-43043MEDIUM5.5IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user....
CVE-2023-38723MEDIUM6.4IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to em...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now