2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34210 | HIGH | 8.8 | 0.6% | Oct 17, 2023 | SQL Injection in create customer group function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticat... |
| CVE-2023-34207 | HIGH | 8.8 | 0.6% | Oct 17, 2023 | Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate... |
| CVE-2023-4215 | HIGH | 7.5 | 0.5% | Oct 17, 2023 | Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability t... |
| CVE-2023-40373 | HIGH | 7.5 | 0.8% | Oct 17, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially cr... |
| CVE-2023-40372 | HIGH | 7.5 | 0.8% | Oct 17, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special... |
| CVE-2023-40374 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special... |
| CVE-2023-30991 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with ... |
| CVE-2023-45131 | HIGH | 7.5 | 1.8% | Oct 16, 2023 | Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticate... |
| CVE-2023-44388 | HIGH | 7.5 | 0.5% | Oct 16, 2023 | Discourse is an open source platform for community discussion. A malicious request can cause production log files to qui... |
| CVE-2023-38740 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a spec... |
| CVE-2023-38728 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic... |
| CVE-2023-45141 | HIGH | 8.8 | 0.3% | Oct 16, 2023 | Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been ide... |
| CVE-2023-45128 | HIGH | 8.8 | 0.3% | Oct 16, 2023 | Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been ide... |
| CVE-2023-42459 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). I... |
| CVE-2023-38720 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 and 11.5 is vulnerable to denial of service with ... |
| CVE-2023-30987 | HIGH | 7.5 | 0.8% | Oct 16, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic... |
| CVE-2023-5133 | HIGH | 7.5 | 0.5% | Oct 16, 2023 | This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted header... |
| CVE-2023-5003 | HIGH | 7.5 | 25.9% | Oct 16, 2023 | The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffe... |
| CVE-2023-4971 | HIGH | 7.2 | 1.0% | Oct 16, 2023 | The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could ... |
| CVE-2023-4861 | HIGH | 7.2 | 1.3% | Oct 16, 2023 | The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments wh... |
| CVE-2023-4776 | HIGH | 8.8 | 0.7% | Oct 16, 2023 | The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimite... |
| CVE-2023-4691 | HIGH | 7.2 | 0.7% | Oct 16, 2023 | The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a ... |
| CVE-2023-4643 | HIGH | 8.8 | 0.8% | Oct 16, 2023 | The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which ... |
| CVE-2023-43121 | HIGH | 7.5 | 1.0% | Oct 16, 2023 | A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.... |
| CVE-2023-43118 | HIGH | 8.8 | 0.3% | Oct 16, 2023 | Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now