2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33524 | MEDIUM | 5.3 | 1.0% | Jun 5, 2023 | Advent/SSC Inc. Tamale RMS < 23.1 is vulnerable to Directory Traversal. If one traverses to the affected URL, one enumer... |
| CVE-2023-3109 | MEDIUM | 5.4 | 0.5% | Jun 5, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository admidio/admidio prior to 4.2.8. |
| CVE-2023-33693 | MEDIUM | 5.5 | 0.4% | Jun 5, 2023 | A buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) ... |
| CVE-2023-33690 | MEDIUM | 6.5 | 0.9% | Jun 5, 2023 | SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special charac... |
| CVE-2023-33518 | MEDIUM | 5.3 | 0.5% | Jun 5, 2023 | emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain... |
| CVE-2023-32766 | MEDIUM | 6.1 | 0.6% | Jun 5, 2023 | Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three ... |
| CVE-2023-2634 | MEDIUM | 4.8 | 0.5% | Jun 5, 2023 | The Get your number WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2023-2572 | MEDIUM | 6.1 | 0.5% | Jun 5, 2023 | The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes... |
| CVE-2023-2571 | MEDIUM | 6.1 | 2.1% | Jun 5, 2023 | The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes... |
| CVE-2023-2503 | MEDIUM | 6.1 | 0.5% | Jun 5, 2023 | The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting i... |
| CVE-2023-2489 | MEDIUM | 4.8 | 0.4% | Jun 5, 2023 | The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape... |
| CVE-2023-2488 | MEDIUM | 6.1 | 0.5% | Jun 5, 2023 | The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape... |
| CVE-2023-2472 | MEDIUM | 6.1 | 0.5% | Jun 5, 2023 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise... |
| CVE-2023-2337 | MEDIUM | 6.1 | 0.5% | Jun 5, 2023 | The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, lead... |
| CVE-2023-2224 | MEDIUM | 4.8 | 0.9% | Jun 5, 2023 | The SEO by 10Web WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2023-0545 | MEDIUM | 4.8 | 0.4% | Jun 5, 2023 | The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2023-0152 | MEDIUM | 5.4 | 0.4% | Jun 5, 2023 | The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes be... |
| CVE-2023-27989 | MEDIUM | 6.5 | 1.0% | Jun 5, 2023 | A buffer overflow vulnerability in the CGI program of the Zyxel NR7101 firmware versions prior to V1.00(ABUV.8)C0 could... |
| CVE-2023-3064 | MEDIUM | 5.3 | 0.6% | Jun 5, 2023 | Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2... |
| CVE-2023-34410 | MEDIUM | 5.3 | 0.7% | Jun 5, 2023 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate valida... |
| CVE-2023-34408 | MEDIUM | 5.4 | 0.7% | Jun 5, 2023 | DokuWiki before 2023-04-04a allows XSS via RSS titles. |
| CVE-2023-32334 | MEDIUM | 5.3 | 0.6% | Jun 5, 2023 | IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL ... |
| CVE-2023-27861 | MEDIUM | 5.9 | 0.3% | Jun 5, 2023 | IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could ... |
| CVE-2023-3095 | MEDIUM | 6.5 | 0.4% | Jun 4, 2023 | Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. |
| CVE-2023-32582 | MEDIUM | 4.8 | 0.4% | Jun 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kyle Maurer Don8 plugin <= 0.4 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now