2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6145 | CRITICAL | 9.8 | 0.5% | Dec 21, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in İstanbul Soft Info... |
| CVE-2023-6122 | MEDIUM | 6.1 | 0.4% | Dec 21, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in İstanbul Soft Info... |
| CVE-2023-49162 | HIGH | 7.5 | 0.4% | Dec 21, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BigCommerce BigCommerce For WordPress.This i... |
| CVE-2023-48288 | HIGH | 7.5 | 0.5% | Dec 21, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HM Plugin WordPress Job Board and Recruitmen... |
| CVE-2023-2487 | HIGH | 7.5 | 0.5% | Dec 21, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orde... |
| CVE-2023-28421 | HIGH | 7.5 | 0.5% | Dec 21, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Winwar Media WordPress Email Marketing Plugi... |
| CVE-2023-49826 | CRITICAL | 9.8 | 0.6% | Dec 21, 2023 | Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce Wor... |
| CVE-2023-49778 | CRITICAL | 9.8 | 0.8% | Dec 21, 2023 | Deserialization of Untrusted Data vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a th... |
| CVE-2023-49762 | HIGH | 7.5 | 0.5% | Dec 21, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AppMySite AppMySite – Create an app with the... |
| CVE-2023-32242 | CRITICAL | 9.8 | 0.8% | Dec 21, 2023 | Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects W... |
| CVE-2023-5594 | HIGH | 8.6 | 0.4% | Dec 21, 2023 | Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certifi... |
| CVE-2023-51656 | CRITICAL | 9.8 | 1.0% | Dec 21, 2023 | Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.1... |
| CVE-2023-50481 | HIGH | 7.5 | 0.3% | Dec 21, 2023 | An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak en... |
| CVE-2023-50477 | CRITICAL | 9.8 | 0.7% | Dec 21, 2023 | An issue was discovered in nos client version 0.6.6, allows remote attackers to escalate privileges via getRPCEndpoint.j... |
| CVE-2023-50475 | CRITICAL | 9.1 | 0.5% | Dec 21, 2023 | An issue was discovered in bcoin-org bcoin version 2.2.0, allows remote attackers to obtain sensitive information via we... |
| CVE-2023-50473 | MEDIUM | 5.4 | 0.4% | Dec 21, 2023 | Cross-Site Scripting (XSS) vulnerability in bill-ahmed qbit-matUI version 1.16.4, allows remote attackers to obtain sens... |
| CVE-2023-5989 | MEDIUM | 6.1 | 0.3% | Dec 21, 2023 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uyumsoft Inform... |
| CVE-2023-5988 | MEDIUM | 6.1 | 0.3% | Dec 21, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uyumsoft Informati... |
| CVE-2023-51655 | CRITICAL | 9.8 | 0.3% | Dec 21, 2023 | In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin ... |
| CVE-2023-50783 | MEDIUM | 6.5 | 1.4% | Dec 21, 2023 | Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the vari... |
| CVE-2023-49920 | MEDIUM | 6.5 | 1.0% | Dec 21, 2023 | Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET reque... |
| CVE-2023-48291 | MEDIUM | 4.3 | 1.8% | Dec 21, 2023 | Apache Airflow, in versions prior to 2.8.0, contains a security vulnerability that allows an authenticated user with lim... |
| CVE-2023-47265 | MEDIUM | 5.4 | 1.3% | Dec 21, 2023 | Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded... |
| CVE-2023-2585 | HIGH | 8.1 | 0.6% | Dec 21, 2023 | Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client coul... |
| CVE-2023-7026 | MEDIUM | 6.5 | 0.6% | Dec 21, 2023 | A vulnerability was found in Lightxun IPTV Gateway up to 20231208. It has been rated as problematic. This issue affects ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now