2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-27868HIGH8.8IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker...
CVE-2023-27867HIGH8.8IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker...
CVE-2023-27558HIGH7.8IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed ser...
CVE-2023-27540HIGH7.5IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a ...
CVE-2023-25478HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Jason Rouet Weather Station plugin <= 3.8.12 versions.
CVE-2023-24405HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin <= 1.9....
CVE-2023-24395HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 Redirect & Thank You Page plugin <= 1.0...
CVE-2023-23993HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com LionScripts: IP Blocker Lite plugin <= 11.1.1 version...
CVE-2023-23897HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Ozette Plugins Simple Mobile URL Redirect plugin <= 1.7.2 versions.
CVE-2023-23869HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions.
CVE-2023-23804HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Feed plugin <= 1.2.7 versions.
CVE-2023-23787HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Redirect Manager plugin <= 1.0.9 versions.
CVE-2023-22695HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.8 versions.
CVE-2023-22694HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Arian Khosravi, Norik Davtian BigContact Contact Page plugin <= 1.5.8...
CVE-2023-22673HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in MageNet Website Monetization by MageNet plugin <= 1.0.29.1 versions.
CVE-2023-1902HIGH8The bluetooth HCI host layer logic not clearing a global reference to a state pointer after handling connection events m...
CVE-2023-1901HIGH8The bluetooth HCI host layer logic not clearing a global reference to a semaphore after synchronously sending HCI comman...
CVE-2023-1597HIGH8.8The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible t...
CVE-2023-1208HIGH7.2This HTTP Headers WordPress plugin before 1.18.11 allows arbitrary data to be written to arbitrary files, leading to a R...
CVE-2023-0359HIGH7.5A missing nullptr-check in handle_ra_input can cause a nullptr-deref.
CVE-2023-37288HIGH7.5SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remot...
CVE-2023-3553HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10...
CVE-2023-3551HIGH7.2 Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
CVE-2023-37270HIGH8.8Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the log...
CVE-2023-37262HIGH8.8CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to versions 1...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now