2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-21218 | CRITICAL | 9.8 | 0.4% | Dec 4, 2023 | In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds ... |
| CVE-2023-21217 | CRITICAL | 9.8 | 0.4% | Dec 4, 2023 | In PMRWritePMPageList of TBD, there is a possible out of bounds write due to an integer overflow. This could lead to loc... |
| CVE-2023-21216 | CRITICAL | 9.8 | 0.4% | Dec 4, 2023 | In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after fre... |
| CVE-2023-21215 | CRITICAL | 9.8 | 0.4% | Dec 4, 2023 | In DevmemIntAcquireRemoteCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition... |
| CVE-2023-21166 | CRITICAL | 9.8 | 0.4% | Dec 4, 2023 | In RGXBackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lea... |
| CVE-2023-21164 | CRITICAL | 9.8 | 0.4% | Dec 4, 2023 | In DevmemIntMapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This cou... |
| CVE-2023-21163 | CRITICAL | 9.8 | 0.4% | Dec 4, 2023 | In PMR_ReadBytes of pmr.c, there is a possible arbitrary code execution due to a use after free. This could lead to loca... |
| CVE-2023-21162 | CRITICAL | 9.8 | 0.4% | Dec 4, 2023 | In RGXUnbackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could l... |
| CVE-2023-6063 | HIGH | 7.5 | 73.7% | Dec 4, 2023 | The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in ... |
| CVE-2023-5990 | MEDIUM | 6.5 | 0.3% | Dec 4, 2023 | The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor WordPress plugin before 3.4.2 does not ... |
| CVE-2023-5979 | MEDIUM | 6.5 | 0.3% | Dec 4, 2023 | The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin p... |
| CVE-2023-5953 | HIGH | 8.8 | 0.5% | Dec 4, 2023 | The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have au... |
| CVE-2023-5952 | CRITICAL | 9.8 | 1.3% | Dec 4, 2023 | The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtnia... |
| CVE-2023-5951 | MEDIUM | 6.1 | 0.5% | Dec 4, 2023 | The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back ... |
| CVE-2023-5884 | MEDIUM | 6.5 | 0.3% | Dec 4, 2023 | The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an u... |
| CVE-2023-5874 | MEDIUM | 4.8 | 0.4% | Dec 4, 2023 | The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-5809 | MEDIUM | 4.8 | 0.4% | Dec 4, 2023 | The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-5762 | HIGH | 8.8 | 2.0% | Dec 4, 2023 | The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows t... |
| CVE-2023-5210 | MEDIUM | 6.1 | 0.4% | Dec 4, 2023 | The AMP+ Plus WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2023-5141 | MEDIUM | 6.1 | 0.4% | Dec 4, 2023 | The BSK Contact Form 7 Blacklist WordPress plugin through 1.0.1 does not sanitise and escape the inserted_count paramete... |
| CVE-2023-5137 | MEDIUM | 4.8 | 0.4% | Dec 4, 2023 | The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which ... |
| CVE-2023-5108 | HIGH | 7.2 | 1.0% | Dec 4, 2023 | The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before usin... |
| CVE-2023-5105 | MEDIUM | 6.5 | 1.0% | Dec 4, 2023 | The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass ... |
| CVE-2023-4460 | MEDIUM | 5.4 | 0.9% | Dec 4, 2023 | The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could a... |
| CVE-2023-49080 | MEDIUM | 4.3 | 0.8% | Dec 4, 2023 | The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now