2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32282 | HIGH | 7.2 | 0.1% | Mar 14, 2024 | Race condition in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalatio... |
| CVE-2023-28746 | MEDIUM | 6.5 | 0.5% | Mar 14, 2024 | Information exposure through microarchitectural state after transient execution from some register files for some Intel(... |
| CVE-2023-28389 | MEDIUM | 6.7 | 0.1% | Mar 14, 2024 | Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authentica... |
| CVE-2023-27502 | LOW | 3.3 | 0.2% | Mar 14, 2024 | Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2... |
| CVE-2023-22655 | MEDIUM | 6.1 | 0.2% | Mar 14, 2024 | Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel... |
| CVE-2023-50168 | HIGH | 7.7 | 0.4% | Mar 14, 2024 | Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation. |
| CVE-2023-38536 | MEDIUM | 6.1 | 0.4% | Mar 13, 2024 | HTML injection in OpenText™ Exceed Turbo X affecting version 12.5.1. The vulnerability could result in Cross site script... |
| CVE-2023-38535 | CRITICAL | 9.8 | 0.3% | Mar 13, 2024 | Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The ... |
| CVE-2023-38534 | HIGH | 7.5 | 0.5% | Mar 13, 2024 | Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerabilit... |
| CVE-2023-50726 | MEDIUM | 6.4 | 0.5% | Mar 13, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows... |
| CVE-2023-41505 | CRITICAL | 9.8 | 0.8% | Mar 13, 2024 | An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 a... |
| CVE-2023-41504 | HIGH | 8.8 | 0.7% | Mar 13, 2024 | SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Sear... |
| CVE-2023-36238 | MEDIUM | 6.5 | 0.5% | Mar 13, 2024 | Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the in... |
| CVE-2023-7015 | MEDIUM | 6.1 | 0.5% | Mar 13, 2024 | The File Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tb' parameter in all ... |
| CVE-2023-6969 | MEDIUM | 4.3 | 0.5% | Mar 13, 2024 | The User Shortcodes Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a... |
| CVE-2023-6957 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2023-6954 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)... |
| CVE-2023-6880 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages pl... |
| CVE-2023-6825 | CRITICAL | 9.9 | 6.0% | Mar 13, 2024 | The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and... |
| CVE-2023-6809 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Custom fields shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf shortc... |
| CVE-2023-6785 | MEDIUM | 5.3 | 0.5% | Mar 13, 2024 | The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in a... |
| CVE-2023-5663 | HIGH | 8.8 | 0.8% | Mar 13, 2024 | The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions ... |
| CVE-2023-52608 | MEDIUM | 4.7 | 0.2% | Mar 13, 2024 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Check mailbox/SMT channel for c... |
| CVE-2023-43043 | MEDIUM | 5.5 | 0.2% | Mar 13, 2024 | IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user.... |
| CVE-2023-38723 | MEDIUM | 6.4 | 0.3% | Mar 13, 2024 | IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to em... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now