2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-51681 | MEDIUM | 6.5 | 0.3% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issu... |
| CVE-2023-6917 | MEDIUM | 6.7 | 0.2% | Feb 28, 2024 | A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels ... |
| CVE-2023-6922 | MEDIUM | 6.5 | 0.5% | Feb 28, 2024 | The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu... |
| CVE-2023-50737 | CRITICAL | 9.1 | 1.0% | Feb 28, 2024 | The SE menu contains information used by Lexmark to diagnose device errors. A vulnerability in one of the SE menu routin... |
| CVE-2023-50736 | CRITICAL | 9 | 0.8% | Feb 28, 2024 | A memory corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerab... |
| CVE-2023-50735 | CRITICAL | 9 | 0.8% | Feb 28, 2024 | A heap corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerabil... |
| CVE-2023-50734 | CRITICAL | 9 | 0.8% | Feb 28, 2024 | A buffer overflow vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerabil... |
| CVE-2023-50303 | MEDIUM | 6.1 | 0.4% | Feb 28, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2023-50380 | MEDIUM | 6.5 | 0.9% | Feb 27, 2024 | XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, whi... |
| CVE-2023-48682 | MEDIUM | 5.4 | 0.3% | Feb 27, 2024 | Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect... |
| CVE-2023-48681 | MEDIUM | 6.1 | 0.3% | Feb 27, 2024 | Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acroni... |
| CVE-2023-48680 | MEDIUM | 5.5 | 0.2% | Feb 27, 2024 | Sensitive information disclosure due to excessive collection of system information. The following products are affected:... |
| CVE-2023-48679 | MEDIUM | 5.4 | 0.3% | Feb 27, 2024 | Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products ... |
| CVE-2023-48678 | MEDIUM | 5.5 | 0.2% | Feb 27, 2024 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber ... |
| CVE-2023-5947 | — | — | — | Feb 27, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-7247. Reason: This candidate is a d... |
| CVE-2023-51747 | HIGH | 7.1 | 1.0% | Feb 27, 2024 | Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter h... |
| CVE-2023-7016 | HIGH | 7.8 | 0.3% | Feb 27, 2024 | A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYST... |
| CVE-2023-5993 | HIGH | 7.8 | 0.2% | Feb 27, 2024 | A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker ... |
| CVE-2023-7203 | MEDIUM | 6.1 | 0.2% | Feb 27, 2024 | The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow us... |
| CVE-2023-7202 | MEDIUM | 6.1 | 0.2% | Feb 27, 2024 | The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX ... |
| CVE-2023-7198 | MEDIUM | 4.3 | 0.4% | Feb 27, 2024 | The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_... |
| CVE-2023-7167 | MEDIUM | 6.1 | 0.4% | Feb 27, 2024 | The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2023-7165 | HIGH | 7.5 | 1.9% | Feb 27, 2024 | The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive d... |
| CVE-2023-7115 | MEDIUM | 4.8 | 0.4% | Feb 27, 2024 | The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could... |
| CVE-2023-6585 | HIGH | 7.5 | 0.6% | Feb 27, 2024 | The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now