2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6447 | MEDIUM | 5.3 | 0.6% | Jan 22, 2024 | The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors t... |
| CVE-2023-6384 | MEDIUM | 4.3 | 0.4% | Jan 22, 2024 | The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to ... |
| CVE-2023-6290 | MEDIUM | 4.8 | 0.4% | Jan 22, 2024 | The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privi... |
| CVE-2023-47747 | MEDIUM | 6.5 | 0.7% | Jan 22, 2024 | IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user... |
| CVE-2023-47158 | MEDIUM | 6.5 | 0.7% | Jan 22, 2024 | IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated u... |
| CVE-2023-47152 | HIGH | 7.5 | 0.6% | Jan 22, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algori... |
| CVE-2023-27859 | MEDIUM | 6.5 | 1.0% | Jan 22, 2024 | IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar fil... |
| CVE-2023-50308 | MEDIUM | 6.5 | 0.8% | Jan 22, 2024 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authen... |
| CVE-2023-48118 | CRITICAL | 9.8 | 1.2% | Jan 22, 2024 | SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code v... |
| CVE-2023-47746 | MEDIUM | 6.5 | 0.7% | Jan 22, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user... |
| CVE-2023-45193 | HIGH | 7.5 | 0.8% | Jan 22, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of ser... |
| CVE-2023-44395 | MEDIUM | 6.5 | 0.6% | Jan 22, 2024 | Autolab is a course management service that enables instructors to offer autograded programming assignments to their stu... |
| CVE-2023-52354 | HIGH | 7.5 | 0.5% | Jan 22, 2024 | chasquid before 1.13 allows SMTP smuggling because LF-terminated lines are accepted. |
| CVE-2023-47352 | HIGH | 8.8 | 0.4% | Jan 22, 2024 | Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID v... |
| CVE-2023-52353 | HIGH | 7.5 | 0.5% | Jan 21, 2024 | An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is m... |
| CVE-2023-6531 | HIGH | 7 | 0.2% | Jan 21, 2024 | A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SK... |
| CVE-2023-7063 | MEDIUM | 6.1 | 0.5% | Jan 20, 2024 | The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all ... |
| CVE-2023-46447 | MEDIUM | 4.3 | 0.4% | Jan 20, 2024 | The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted gluco... |
| CVE-2023-51925 | CRITICAL | 9.8 | 1.0% | Jan 20, 2024 | An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of ... |
| CVE-2023-51924 | CRITICAL | 9.8 | 1.0% | Jan 20, 2024 | An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows ... |
| CVE-2023-51906 | CRITICAL | 9.8 | 1.2% | Jan 20, 2024 | An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the Servic... |
| CVE-2023-47024 | HIGH | 8.8 | 0.3% | Jan 20, 2024 | Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieve... |
| CVE-2023-51928 | CRITICAL | 9.8 | 1.0% | Jan 20, 2024 | An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of ... |
| CVE-2023-51927 | CRITICAL | 9.8 | 0.6% | Jan 20, 2024 | YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScri... |
| CVE-2023-51926 | HIGH | 7.5 | 0.6% | Jan 20, 2024 | YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonS... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now