2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31505 | HIGH | 7.2 | 1.2% | Jan 31, 2024 | An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrar... |
| CVE-2023-2439 | MEDIUM | 5.4 | 0.3% | Jan 31, 2024 | The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up... |
| CVE-2023-51204 | — | — | — | Jan 30, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-51202 | — | — | — | Jan 30, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-51198 | — | — | — | Jan 30, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-51197 | — | — | — | Jan 30, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-5389 | HIGH | 7.5 | 0.8% | Jan 30, 2024 | An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ... |
| CVE-2023-6258 | HIGH | 8.1 | 0.6% | Jan 30, 2024 | A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography St... |
| CVE-2023-46231 | HIGH | 7.2 | 0.5% | Jan 30, 2024 | In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when... |
| CVE-2023-46230 | MEDIUM | 4.9 | 0.4% | Jan 30, 2024 | In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files. |
| CVE-2023-37518 | HIGH | 8.8 | 0.4% | Jan 30, 2024 | HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary... |
| CVE-2023-6943 | CRITICAL | 9.8 | 1.8% | Jan 30, 2024 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric ... |
| CVE-2023-6942 | HIGH | 7.5 | 0.9% | Jan 30, 2024 | Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5... |
| CVE-2023-6374 | HIGH | 7.5 | 0.8% | Jan 30, 2024 | Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 ... |
| CVE-2023-36260 | HIGH | 7.5 | 1.1% | Jan 30, 2024 | An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of servi... |
| CVE-2023-36259 | MEDIUM | 5.4 | 0.4% | Jan 30, 2024 | Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbi... |
| CVE-2023-7225 | MEDIUM | 5.4 | 0.5% | Jan 30, 2024 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and heig... |
| CVE-2023-52071 | — | — | — | Jan 30, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-45930 | — | — | — | Jan 30, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-45928 | — | — | — | Jan 30, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-45926 | — | — | — | Jan 30, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-45923 | — | — | — | Jan 30, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-5372 | HIGH | 7.2 | 28.5% | Jan 30, 2024 | The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and N... |
| CVE-2023-51982 | CRITICAL | 9.8 | 0.7% | Jan 30, 2024 | CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password a... |
| CVE-2023-51843 | HIGH | 8.2 | 0.5% | Jan 30, 2024 | react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now