2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32589 | HIGH | 8.8 | 0.3% | May 20, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in PingOnline Dyslexiefont Free plugin <= 1.0.0 versions. |
| CVE-2023-24414 | HIGH | 8.8 | 0.3% | May 20, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <=... |
| CVE-2023-23890 | HIGH | 8.8 | 0.3% | May 20, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in LJ Apps WP Airbnb Review Slider plugin <= 3.2 versions. |
| CVE-2023-22689 | HIGH | 8.8 | 0.3% | May 20, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3 versions. |
| CVE-2023-33244 | HIGH | 8.2 | 0.5% | May 20, 2023 | Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) v... |
| CVE-2023-32700 | HIGH | 7.8 | 0.8% | May 20, 2023 | LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted s... |
| CVE-2023-1696 | HIGH | 7.5 | 0.4% | May 20, 2023 | The multimedia video module has a vulnerability in data processing.Successful exploitation of this vulnerability may aff... |
| CVE-2023-1694 | HIGH | 7.5 | 0.4% | May 20, 2023 | The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may af... |
| CVE-2023-1693 | HIGH | 7.5 | 0.4% | May 20, 2023 | The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may af... |
| CVE-2023-1692 | HIGH | 7.5 | 0.4% | May 20, 2023 | The window management module lacks permission verification.Successful exploitation of this vulnerability may affect conf... |
| CVE-2023-2736 | HIGH | 8 | 0.4% | May 20, 2023 | The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.... |
| CVE-2023-32679 | HIGH | 7.2 | 1.8% | May 19, 2023 | Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension ... |
| CVE-2023-20881 | HIGH | 8.1 | 0.4% | May 19, 2023 | Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override othe... |
| CVE-2023-30199 | HIGH | 7.5 | 0.7% | May 19, 2023 | Prestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/downl... |
| CVE-2023-2806 | HIGH | 8.8 | 1.0% | May 19, 2023 | A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the ... |
| CVE-2023-28045 | HIGH | 7.1 | 0.2% | May 19, 2023 | Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with l... |
| CVE-2023-33240 | HIGH | 7.8 | 0.2% | May 19, 2023 | Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53... |
| CVE-2023-1618 | HIGH | 8.6 | 1.1% | May 19, 2023 | Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 ***... |
| CVE-2023-24833 | HIGH | 7.5 | 0.6% | May 18, 2023 | A use-after-free in BigIntPrimitive addition in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could ha... |
| CVE-2023-24832 | HIGH | 7.5 | 0.7% | May 18, 2023 | A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27fdd8b01f103e198708 could have been used b... |
| CVE-2023-23759 | HIGH | 7.5 | 0.7% | May 18, 2023 | There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. Th... |
| CVE-2023-2024 | HIGH | 7.5 | 1.1% | May 18, 2023 | Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unau... |
| CVE-2023-31655 | HIGH | 7.5 | 1.0% | May 18, 2023 | redis v7.0.10 was discovered to contain a segmentation violation. This vulnerability allows attackers to cause a Denial ... |
| CVE-2023-32100 | HIGH | 7.5 | 0.5% | May 18, 2023 | Compiler removal of buffer clearing in sli_se_driver_mac_compute in Silicon Labs Gecko Platform SDK v4.2.1 and earli... |
| CVE-2023-32099 | HIGH | 7.5 | 0.5% | May 18, 2023 | Compiler removal of buffer clearing in sli_se_sign_hash in Silicon Labs Gecko Platform SDK v4.2.1 and earlier r... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now