2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-34210HIGH8.8SQL Injection in create customer group function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticat...
CVE-2023-34207HIGH8.8Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate...
CVE-2023-4215HIGH7.5Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability t...
CVE-2023-40373HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially cr...
CVE-2023-40372HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special...
CVE-2023-40374HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special...
CVE-2023-30991HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with ...
CVE-2023-45131HIGH7.5Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticate...
CVE-2023-44388HIGH7.5Discourse is an open source platform for community discussion. A malicious request can cause production log files to qui...
CVE-2023-38740HIGH7.5IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a spec...
CVE-2023-38728HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic...
CVE-2023-45141HIGH8.8Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been ide...
CVE-2023-45128HIGH8.8Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been ide...
CVE-2023-42459HIGH7.5Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). I...
CVE-2023-38720HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 and 11.5 is vulnerable to denial of service with ...
CVE-2023-30987HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic...
CVE-2023-5133HIGH7.5This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted header...
CVE-2023-5003HIGH7.5The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffe...
CVE-2023-4971HIGH7.2The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could ...
CVE-2023-4861HIGH7.2The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments wh...
CVE-2023-4776HIGH8.8The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimite...
CVE-2023-4691HIGH7.2The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a ...
CVE-2023-4643HIGH8.8The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which ...
CVE-2023-43121HIGH7.5A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32....
CVE-2023-43118HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now