2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26067 | HIGH | 8.1 | 37.8% | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4). |
| CVE-2023-28206 | HIGH | 8.6 | 24.5% | Apr 10, 2023 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5,... |
| CVE-2023-28205 | HIGH | 8.8 | 27.1% | Apr 10, 2023 | A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 a... |
| CVE-2023-26986 | HIGH | 7.8 | 0.5% | Apr 10, 2023 | An issue in China Mobile OA Mailbox PC v2.9.23 allows remote attackers to execute arbitrary commands on a victim host vi... |
| CVE-2023-26919 | HIGH | 7.2 | 0.6% | Apr 10, 2023 | delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the lo... |
| CVE-2023-1970 | HIGH | 7.2 | 1.0% | Apr 10, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in yuan1994 tpAdmin... |
| CVE-2023-1381 | HIGH | 8.8 | 1.7% | Apr 10, 2023 | The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the ima... |
| CVE-2023-1425 | HIGH | 7.2 | 0.9% | Apr 10, 2023 | The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.... |
| CVE-2023-1406 | HIGH | 8.8 | 1.5% | Apr 10, 2023 | The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not exec... |
| CVE-2023-26860 | HIGH | 8.8 | 1.1% | Apr 10, 2023 | SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges v... |
| CVE-2023-26774 | HIGH | 7.5 | 1.4% | Apr 10, 2023 | An issue found in Sales Tracker Management System v.1.0 allows a remote attacker to access sensitive information via sal... |
| CVE-2023-27730 | HIGH | 7.5 | 0.7% | Apr 9, 2023 | Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.... |
| CVE-2023-27729 | HIGH | 7.5 | 0.7% | Apr 9, 2023 | Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c. |
| CVE-2023-27728 | HIGH | 7.5 | 0.7% | Apr 9, 2023 | Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_v... |
| CVE-2023-27727 | HIGH | 7.5 | 0.7% | Apr 9, 2023 | Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_func... |
| CVE-2023-1960 | HIGH | 8.8 | 0.7% | Apr 8, 2023 | A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. This issue ... |
| CVE-2023-1959 | HIGH | 8.8 | 0.7% | Apr 8, 2023 | A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. This v... |
| CVE-2023-1957 | HIGH | 8.8 | 0.7% | Apr 8, 2023 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0... |
| CVE-2023-1956 | HIGH | 8.8 | 1.1% | Apr 8, 2023 | A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by thi... |
| CVE-2023-1954 | HIGH | 8.8 | 0.7% | Apr 8, 2023 | A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been rated as critical. This is... |
| CVE-2023-1953 | HIGH | 8.8 | 0.7% | Apr 8, 2023 | A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been declared as critical. This... |
| CVE-2023-27180 | HIGH | 7.5 | 1.1% | Apr 7, 2023 | GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup feature which is acces... |
| CVE-2023-28710 | HIGH | 7.5 | 2.2% | Apr 7, 2023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Spark Provider.This issue affects A... |
| CVE-2023-28707 | HIGH | 7.5 | 2.1% | Apr 7, 2023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects A... |
| CVE-2023-27876 | HIGH | 7.1 | 0.9% | Apr 7, 2023 | IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attack... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now