2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6081 | MEDIUM | 5.4 | 0.4% | Feb 12, 2024 | The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-6036 | CRITICAL | 9.8 | 1.8% | Feb 12, 2024 | The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checkin... |
| CVE-2023-6681 | MEDIUM | 5.3 | 0.9% | Feb 12, 2024 | A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possib... |
| CVE-2023-46615 | CRITICAL | 9.8 | 0.8% | Feb 12, 2024 | Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a... |
| CVE-2023-41708 | MEDIUM | 5.4 | 0.5% | Feb 12, 2024 | References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app ... |
| CVE-2023-41707 | MEDIUM | 6.5 | 0.8% | Feb 12, 2024 | Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to ... |
| CVE-2023-41706 | MEDIUM | 6.5 | 0.8% | Feb 12, 2024 | Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource thre... |
| CVE-2023-41705 | MEDIUM | 6.5 | 0.8% | Feb 12, 2024 | Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to h... |
| CVE-2023-41704 | MEDIUM | 6.1 | 0.5% | Feb 12, 2024 | Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine... |
| CVE-2023-41703 | MEDIUM | 6.1 | 0.5% | Feb 12, 2024 | User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a use... |
| CVE-2023-51403 | MEDIUM | 5.4 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicdark Restaurant... |
| CVE-2023-51370 | MEDIUM | 4.8 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam WP Chat ... |
| CVE-2023-50875 | MEDIUM | 5.4 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei ... |
| CVE-2023-47526 | MEDIUM | 4.8 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team... |
| CVE-2023-52429 | MEDIUM | 5.5 | 0.2% | Feb 12, 2024 | dm_table_create in drivers/md/dm-table.c in the Linux kernel through 6.7.4 can attempt to (in alloc_targets) allocate mo... |
| CVE-2023-52428 | HIGH | 7.5 | 0.8% | Feb 11, 2024 | In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a larg... |
| CVE-2023-52427 | HIGH | 7.5 | 0.6% | Feb 11, 2024 | In OpenDDS through 3.27, there is a segmentation fault for a DataWriter with a large value of resource_limits.max_sample... |
| CVE-2023-50957 | HIGH | 7.2 | 0.4% | Feb 10, 2024 | IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtain... |
| CVE-2023-51493 | MEDIUM | 5.4 | 0.3% | Feb 10, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Howard Ehrenberg C... |
| CVE-2023-51492 | MEDIUM | 5.4 | 0.3% | Feb 10, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If So Plugin If-So... |
| CVE-2023-51488 | MEDIUM | 6.1 | 0.4% | Feb 10, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. C... |
| CVE-2023-51485 | MEDIUM | 5.4 | 0.3% | Feb 10, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Hosting Pay wit... |
| CVE-2023-51480 | MEDIUM | 5.4 | 0.3% | Feb 10, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 Active ... |
| CVE-2023-51415 | MEDIUM | 5.4 | 0.3% | Feb 10, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GiveWP GiveWP – Do... |
| CVE-2023-51404 | MEDIUM | 5.4 | 0.3% | Feb 10, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyAgilePrivacy My ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now