2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-51681MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issu...
CVE-2023-6917MEDIUM6.7A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels ...
CVE-2023-6922MEDIUM6.5The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu...
CVE-2023-50737CRITICAL9.1The SE menu contains information used by Lexmark to diagnose device errors. A vulnerability in one of the SE menu routin...
CVE-2023-50736CRITICAL9A memory corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerab...
CVE-2023-50735CRITICAL9A heap corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerabil...
CVE-2023-50734CRITICAL9A buffer overflow vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerabil...
CVE-2023-50303MEDIUM6.1IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2023-50380MEDIUM6.5XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, whi...
CVE-2023-48682MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect...
CVE-2023-48681MEDIUM6.1Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acroni...
CVE-2023-48680MEDIUM5.5Sensitive information disclosure due to excessive collection of system information. The following products are affected:...
CVE-2023-48679MEDIUM5.4Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products ...
CVE-2023-48678MEDIUM5.5Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber ...
CVE-2023-5947Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-7247. Reason: This candidate is a d...
CVE-2023-51747HIGH7.1Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter h...
CVE-2023-7016HIGH7.8A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYST...
CVE-2023-5993HIGH7.8A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker ...
CVE-2023-7203MEDIUM6.1The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow us...
CVE-2023-7202MEDIUM6.1The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX ...
CVE-2023-7198MEDIUM4.3The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_...
CVE-2023-7167MEDIUM6.1The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-7165HIGH7.5The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive d...
CVE-2023-7115MEDIUM4.8The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could...
CVE-2023-6585HIGH7.5The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now