2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49853HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in PayTR Ödeme ve Elektronik Para Kuruluşu A.Ş. PayTR Taksit Tablosu – W...
CVE-2023-49844HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Kevin Ohashi WPPerformanceTester.This issue affects WPPerformanceTest...
CVE-2023-49843HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in QuanticEdge First Order Discount Woocommerce.This issue affects First...
CVE-2023-49840HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Curr...
CVE-2023-46177HIGH7.5IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker co...
CVE-2023-6228LOW3.3An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may ...
CVE-2023-5384LOW2.7A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credenti...
CVE-2023-5236MEDIUM6.5A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated at...
CVE-2023-5115MEDIUM6.3An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a mal...
CVE-2023-5056MEDIUM4.1A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that woul...
CVE-2023-4320HIGH7.5An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attack...
CVE-2023-47038HIGH7.8A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled...
CVE-2023-3629MEDIUM6.5A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permission...
CVE-2023-3628MEDIUM6.5A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. ...
CVE-2023-3430HIGH7.5A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file. ...
CVE-2023-39509HIGH7.2A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative right...
CVE-2023-35867MEDIUM5.9An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthe...
CVE-2023-32230HIGH7.5An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthentica...
CVE-2023-28053MEDIUM5.3 Dell NetWorker Virtual Edition versions 19.8 and below contain the use of deprecated cryptographic algorithms in the SS...
CVE-2023-50372HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Post Type Page Template.This issue affects C...
CVE-2023-49855HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in BinaryCarpenter Menu Bar Cart Icon For WooCommerce By Binary Carpente...
CVE-2023-49854HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Tribe Interactive Caddy – Smart Side Cart for WooCommerce.This issue ...
CVE-2023-32728CRITICAL9.8The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resul...
CVE-2023-32727HIGH7.2An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious comman...
CVE-2023-32726HIGH8.1The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS se...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now