2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6447MEDIUM5.3The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors t...
CVE-2023-6384MEDIUM4.3The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to ...
CVE-2023-6290MEDIUM4.8The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privi...
CVE-2023-47747MEDIUM6.5IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user...
CVE-2023-47158MEDIUM6.5IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated u...
CVE-2023-47152HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algori...
CVE-2023-27859MEDIUM6.5IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar fil...
CVE-2023-50308MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authen...
CVE-2023-48118CRITICAL9.8SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-47746MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user...
CVE-2023-45193HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of ser...
CVE-2023-44395MEDIUM6.5Autolab is a course management service that enables instructors to offer autograded programming assignments to their stu...
CVE-2023-52354HIGH7.5chasquid before 1.13 allows SMTP smuggling because LF-terminated lines are accepted.
CVE-2023-47352HIGH8.8Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID v...
CVE-2023-52353HIGH7.5An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is m...
CVE-2023-6531HIGH7A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SK...
CVE-2023-7063MEDIUM6.1The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all ...
CVE-2023-46447MEDIUM4.3The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted gluco...
CVE-2023-51925CRITICAL9.8An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of ...
CVE-2023-51924CRITICAL9.8An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows ...
CVE-2023-51906CRITICAL9.8An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the Servic...
CVE-2023-47024HIGH8.8Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieve...
CVE-2023-51928CRITICAL9.8An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of ...
CVE-2023-51927CRITICAL9.8YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScri...
CVE-2023-51926HIGH7.5YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonS...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now