2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6807 | MEDIUM | 5.4 | 0.4% | Feb 5, 2024 | The GeneratePress Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom meta... |
| CVE-2023-6701 | MEDIUM | 5.4 | 0.5% | Feb 5, 2024 | The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom text fie... |
| CVE-2023-6700 | HIGH | 8.8 | 1.5% | Feb 5, 2024 | The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due t... |
| CVE-2023-6635 | HIGH | 7.2 | 1.6% | Feb 5, 2024 | The EditorsKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the '... |
| CVE-2023-6557 | MEDIUM | 5.3 | 0.6% | Feb 5, 2024 | The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ... |
| CVE-2023-6526 | MEDIUM | 5.4 | 0.4% | Feb 5, 2024 | The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via c... |
| CVE-2023-4637 | MEDIUM | 5.3 | 0.6% | Feb 5, 2024 | The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the r... |
| CVE-2023-34042 | MEDIUM | 5.5 | 0.2% | Feb 5, 2024 | The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extra... |
| CVE-2023-22819 | MEDIUM | 4.9 | 0.8% | Feb 5, 2024 | An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to co... |
| CVE-2023-22817 | MEDIUM | 5.5 | 0.2% | Feb 5, 2024 | Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL ... |
| CVE-2023-51951 | CRITICAL | 9.8 | 1.4% | Feb 5, 2024 | SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id... |
| CVE-2023-50782 | HIGH | 7.5 | 1.1% | Feb 5, 2024 | A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages... |
| CVE-2023-50781 | HIGH | 7.5 | 1.1% | Feb 5, 2024 | A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that us... |
| CVE-2023-27318 | HIGH | 7.5 | 0.7% | Feb 5, 2024 | StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a Denial of Service (D... |
| CVE-2023-6874 | HIGH | 7.5 | 0.4% | Feb 5, 2024 | Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number |
| CVE-2023-6028 | MEDIUM | 6.1 | 0.4% | Feb 5, 2024 | A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Auto... |
| CVE-2023-47355 | HIGH | 7.5 | 0.8% | Feb 5, 2024 | The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broa... |
| CVE-2023-7216 | MEDIUM | 5.3 | 0.9% | Feb 5, 2024 | A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker t... |
| CVE-2023-52138 | CRITICAL | 9.6 | 1.7% | Feb 5, 2024 | Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerab... |
| CVE-2023-5643 | HIGH | 7.8 | 0.2% | Feb 5, 2024 | Out-of-bounds Write vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5... |
| CVE-2023-5249 | HIGH | 7 | 0.2% | Feb 5, 2024 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-... |
| CVE-2023-7077 | CRITICAL | 9.8 | 0.7% | Feb 5, 2024 | Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X... |
| CVE-2023-5800 | HIGH | 8.8 | 0.7% | Feb 5, 2024 | Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a suffic... |
| CVE-2023-5677 | HIGH | 8.8 | 0.6% | Feb 5, 2024 | Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have... |
| CVE-2023-51504 | MEDIUM | 5.4 | 0.7% | Feb 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now