2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21667 | MEDIUM | 6.5 | 0.3% | Sep 5, 2023 | Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard. |
| CVE-2023-36307 | MEDIUM | 5.5 | 0.2% | Sep 5, 2023 | ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField ... |
| CVE-2023-36308 | MEDIUM | 5.5 | 0.4% | Sep 5, 2023 | disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Graysc... |
| CVE-2023-4636 | MEDIUM | 4.8 | 0.9% | Sep 5, 2023 | The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i... |
| CVE-2023-29261 | MEDIUM | 5.5 | 0.2% | Sep 5, 2023 | IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain ... |
| CVE-2023-22870 | MEDIUM | 5.9 | 0.3% | Sep 5, 2023 | IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in... |
| CVE-2023-32338 | MEDIUM | 5.5 | 0.2% | Sep 5, 2023 | IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in pla... |
| CVE-2023-41057 | MEDIUM | 5.5 | 0.3% | Sep 4, 2023 | hyper-bump-it is a command line tool for updating the version in project files.`hyper-bump-it` reads a file glob pattern... |
| CVE-2023-41052 | MEDIUM | 5.3 | 0.5% | Sep 4, 2023 | Vyper is a Pythonic Smart Contract Language. In affected versions the order of evaluation of the arguments of the builti... |
| CVE-2023-40015 | MEDIUM | 5.3 | 0.4% | Sep 4, 2023 | Vyper is a Pythonic Smart Contract Language. For the following (probably non-exhaustive) list of expressions, the compil... |
| CVE-2023-4758 | MEDIUM | 5.5 | 0.3% | Sep 4, 2023 | Buffer Over-read in GitHub repository gpac/gpac prior to 2.3-DEV. |
| CVE-2023-4755 | MEDIUM | 5.5 | 0.3% | Sep 4, 2023 | Use After Free in GitHub repository gpac/gpac prior to 2.3-DEV. |
| CVE-2023-3221 | MEDIUM | 5.3 | 0.5% | Sep 4, 2023 | User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacke... |
| CVE-2023-4587 | MEDIUM | 5.5 | 0.2% | Sep 4, 2023 | An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local ... |
| CVE-2023-4298 | MEDIUM | 4.8 | 0.4% | Sep 4, 2023 | The 123.chat WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2023-4284 | MEDIUM | 6.1 | 0.7% | Sep 4, 2023 | The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back ... |
| CVE-2023-4269 | MEDIUM | 4.3 | 0.4% | Sep 4, 2023 | The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowin... |
| CVE-2023-4254 | MEDIUM | 4.8 | 0.4% | Sep 4, 2023 | The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2023-4253 | MEDIUM | 4.8 | 0.4% | Sep 4, 2023 | The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2023-4151 | MEDIUM | 6.1 | 0.6% | Sep 4, 2023 | The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back... |
| CVE-2023-4059 | MEDIUM | 4.3 | 0.2% | Sep 4, 2023 | The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allow... |
| CVE-2023-40214 | MEDIUM | 6.1 | 0.3% | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vathemes Business Pro theme <= 1.10.4 versions. |
| CVE-2023-40205 | MEDIUM | 6.1 | 0.3% | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pixelgrade PixTypes plugin <= 1.4.15 versions. |
| CVE-2023-40197 | MEDIUM | 5.4 | 0.3% | Sep 4, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Devaldi Ltd flowpaper plugin <= 1.9.9 versions. |
| CVE-2023-40196 | MEDIUM | 6.1 | 0.3% | Sep 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now