2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4040 | MEDIUM | 5.3 | 0.4% | Aug 18, 2023 | The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to... |
| CVE-2023-31492 | MEDIUM | 6.5 | 5.3% | Aug 17, 2023 | Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of u... |
| CVE-2023-28690 | MEDIUM | 4.8 | 0.4% | Aug 17, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.5 vers... |
| CVE-2023-39974 | MEDIUM | 5.3 | 0.4% | Aug 17, 2023 | Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized ac... |
| CVE-2023-39973 | MEDIUM | 4.3 | 0.3% | Aug 17, 2023 | Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal ... |
| CVE-2023-39972 | MEDIUM | 4.3 | 0.3% | Aug 17, 2023 | Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized users to cre... |
| CVE-2023-39971 | MEDIUM | 6.1 | 0.3% | Aug 17, 2023 | Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla ... |
| CVE-2023-40168 | MEDIUM | 6.5 | 0.6% | Aug 17, 2023 | TurboWarp is a desktop application that compiles scratch projects to JavaScript. TurboWarp Desktop versions prior to ver... |
| CVE-2023-36847 | MEDIUM | 5.3 | 84.7% | Aug 17, 2023 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthe... |
| CVE-2023-36846 | MEDIUM | 5.3 | 94.2% | Aug 17, 2023 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauth... |
| CVE-2023-36844 | MEDIUM | 5.3 | 89.6% | Aug 17, 2023 | A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthen... |
| CVE-2023-31942 | MEDIUM | 4.8 | 0.6% | Aug 17, 2023 | Cross Site Scripting vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitr... |
| CVE-2023-39743 | MEDIUM | 5.3 | 0.7% | Aug 17, 2023 | lrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c. |
| CVE-2023-39741 | MEDIUM | 5.5 | 0.3% | Aug 17, 2023 | lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/l... |
| CVE-2023-38905 | MEDIUM | 5.5 | 0.3% | Aug 17, 2023 | SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via th... |
| CVE-2023-4029 | MEDIUM | 6.7 | 0.2% | Aug 17, 2023 | A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow ... |
| CVE-2023-4028 | MEDIUM | 6.7 | 0.2% | Aug 17, 2023 | A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may... |
| CVE-2023-34419 | MEDIUM | 6.7 | 0.2% | Aug 17, 2023 | A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an att... |
| CVE-2023-31079 | MEDIUM | 5.4 | 0.4% | Aug 17, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Roberts Tippy plugin <= 6.2.1 versions. |
| CVE-2023-31072 | MEDIUM | 6.1 | 0.4% | Aug 17, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Praveen Goswami Advanced Category Template plugin <= 0.1 v... |
| CVE-2023-28783 | MEDIUM | 5.4 | 0.4% | Aug 17, 2023 | Auth. (shop manager+) Stored Cross-Site Scripting (XSS) vulnerability in PHPRADAR Woocommerce Tip/Donation plugin <= 1.2... |
| CVE-2023-28693 | MEDIUM | 6.1 | 0.4% | Aug 17, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Balasaheb Bhise Advanced Youtube Channel Pagination plugin... |
| CVE-2023-34412 | MEDIUM | 4.8 | 0.3% | Aug 17, 2023 | A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 ... |
| CVE-2023-4394 | MEDIUM | 6 | 0.2% | Aug 17, 2023 | A use-after-free flaw was found in btrfs_get_dev_args_from_path in fs/btrfs/volumes.c in btrfs file-system in the Linux ... |
| CVE-2023-31091 | MEDIUM | 4.8 | 0.4% | Aug 17, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now