2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6807MEDIUM5.4The GeneratePress Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom meta...
CVE-2023-6701MEDIUM5.4The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text fie...
CVE-2023-6700HIGH8.8The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due t...
CVE-2023-6635HIGH7.2The EditorsKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the '...
CVE-2023-6557MEDIUM5.3The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ...
CVE-2023-6526MEDIUM5.4The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via c...
CVE-2023-4637MEDIUM5.3The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the r...
CVE-2023-34042MEDIUM5.5The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extra...
CVE-2023-22819MEDIUM4.9An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to co...
CVE-2023-22817MEDIUM5.5Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL ...
CVE-2023-51951CRITICAL9.8SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id...
CVE-2023-50782HIGH7.5A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages...
CVE-2023-50781HIGH7.5A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that us...
CVE-2023-27318HIGH7.5StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a Denial of Service (D...
CVE-2023-6874HIGH7.5Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number
CVE-2023-6028MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Auto...
CVE-2023-47355HIGH7.5The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broa...
CVE-2023-7216MEDIUM5.3A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker t...
CVE-2023-52138CRITICAL9.6Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerab...
CVE-2023-5643HIGH7.8Out-of-bounds Write vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5...
CVE-2023-5249HIGH7Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-...
CVE-2023-7077CRITICAL9.8Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X...
CVE-2023-5800HIGH8.8Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a suffic...
CVE-2023-5677HIGH8.8Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have...
CVE-2023-51504MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now