2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32335 | HIGH | 7.5 | 0.5% | Mar 13, 2024 | IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL para... |
| CVE-2023-28517 | MEDIUM | 5.4 | 0.3% | Mar 13, 2024 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerabilit... |
| CVE-2023-4839 | MEDIUM | 4.8 | 0.3% | Mar 13, 2024 | The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and incl... |
| CVE-2023-7072 | HIGH | 7.5 | 0.6% | Mar 12, 2024 | The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all v... |
| CVE-2023-43279 | MEDIUM | 6.5 | 0.7% | Mar 12, 2024 | Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application ... |
| CVE-2023-43292 | MEDIUM | 6.1 | 0.4% | Mar 12, 2024 | Cross Site Scripting vulnerability in My Food Recipe Using PHP with Source Code v.1.0 allows a local attacker to execute... |
| CVE-2023-42308 | MEDIUM | 6.1 | 0.3% | Mar 12, 2024 | Cross Site Scripting (XSS) vulnerability in Manage Fastrack Subjects in Code-Projects Exam Form Submission 1.0 allows at... |
| CVE-2023-42307 | MEDIUM | 6.1 | 0.4% | Mar 12, 2024 | Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary cod... |
| CVE-2023-5410 | HIGH | 8.2 | 0.2% | Mar 12, 2024 | A potential security vulnerability has been reported in the system BIOS of certain HP PC products, which might allow mem... |
| CVE-2023-30968 | MEDIUM | 6.8 | 0.5% | Mar 12, 2024 | One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could h... |
| CVE-2023-4780 | — | — | — | Mar 12, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-0590. Reason: This candidate is a d... |
| CVE-2023-48788 | CRITICAL | 9.8 | 97.6% | Mar 12, 2024 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS versio... |
| CVE-2023-47534 | HIGH | 8.8 | 1.1% | Mar 12, 2024 | A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.... |
| CVE-2023-46717 | HIGH | 8.8 | 0.6% | Mar 12, 2024 | An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and ve... |
| CVE-2023-42790 | HIGH | 8.1 | 1.1% | Mar 12, 2024 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiO... |
| CVE-2023-42789 | CRITICAL | 9.8 | 3.3% | Mar 12, 2024 | A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 ... |
| CVE-2023-41842 | MEDIUM | 6.7 | 0.2% | Mar 12, 2024 | A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged atta... |
| CVE-2023-36554 | CRITICAL | 9.8 | 0.8% | Mar 12, 2024 | A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0... |
| CVE-2023-45793 | MEDIUM | 5.5 | 0.1% | Mar 12, 2024 | A vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does no... |
| CVE-2023-41313 | CRITICAL | 9.8 | 1.0% | Mar 12, 2024 | The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended ... |
| CVE-2023-4731 | MEDIUM | 4.3 | 0.3% | Mar 12, 2024 | The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_end... |
| CVE-2023-4729 | MEDIUM | 4.3 | 0.2% | Mar 12, 2024 | The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish... |
| CVE-2023-4728 | MEDIUM | 5.4 | 0.3% | Mar 12, 2024 | The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2023-4629 | MEDIUM | 4.3 | 0.2% | Mar 12, 2024 | The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_co... |
| CVE-2023-4628 | MEDIUM | 4.3 | 0.2% | Mar 12, 2024 | The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflo... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now