2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2978 | MEDIUM | 4.3 | 0.7% | May 30, 2023 | A vulnerability was found in Abstrium Pydio Cells 4.2.0. It has been rated as problematic. Affected by this issue is som... |
| CVE-2023-2650 | MEDIUM | 6.5 | 76.5% | May 30, 2023 | Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Imp... |
| CVE-2023-2973 | MEDIUM | 6.1 | 0.6% | May 30, 2023 | A vulnerability, which was classified as problematic, has been found in SourceCodester Students Online Internship Timesh... |
| CVE-2023-2518 | MEDIUM | 6.1 | 1.1% | May 30, 2023 | The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it... |
| CVE-2023-2470 | MEDIUM | 4.8 | 0.5% | May 30, 2023 | The Add to Feedly WordPress plugin through 1.2.11 does not sanitize and escape its settings, allowing high-privilege use... |
| CVE-2023-2296 | MEDIUM | 6.1 | 0.5% | May 30, 2023 | The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading t... |
| CVE-2023-2287 | MEDIUM | 4.3 | 0.6% | May 30, 2023 | The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo imp... |
| CVE-2023-2256 | MEDIUM | 6.1 | 1.0% | May 30, 2023 | The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL paramet... |
| CVE-2023-2223 | MEDIUM | 4.8 | 0.6% | May 30, 2023 | The Login rebuilder WordPress plugin before 2.8.1 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2023-2113 | MEDIUM | 4.8 | 0.5% | May 30, 2023 | The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export,... |
| CVE-2023-2111 | MEDIUM | 4.9 | 0.8% | May 30, 2023 | The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL quer... |
| CVE-2023-2023 | MEDIUM | 6.1 | 1.7% | May 30, 2023 | The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading... |
| CVE-2023-1524 | MEDIUM | 6.5 | 0.7% | May 30, 2023 | The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files.... |
| CVE-2023-0733 | MEDIUM | 6.1 | 0.5% | May 30, 2023 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow u... |
| CVE-2023-0443 | MEDIUM | 5.3 | 0.6% | May 30, 2023 | The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker ... |
| CVE-2023-33955 | MEDIUM | 5.3 | 0.6% | May 30, 2023 | Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the orig... |
| CVE-2023-33186 | MEDIUM | 6.1 | 0.6% | May 30, 2023 | Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and ch... |
| CVE-2023-33183 | MEDIUM | 4.3 | 0.4% | May 30, 2023 | Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the websi... |
| CVE-2023-2970 | MEDIUM | 6.5 | 0.9% | May 30, 2023 | A vulnerability classified as problematic was found in MindSpore 2.0.0-alpha/2.0.0-rc1. This vulnerability affects the f... |
| CVE-2023-33182 | MEDIUM | 4.3 | 0.8% | May 30, 2023 | Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsani... |
| CVE-2023-32685 | MEDIUM | 5.4 | 0.5% | May 30, 2023 | Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements und... |
| CVE-2023-34204 | MEDIUM | 6.5 | 0.6% | May 30, 2023 | imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these ar... |
| CVE-2023-32691 | MEDIUM | 5.9 | 0.6% | May 30, 2023 | gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys sh... |
| CVE-2023-32687 | MEDIUM | 6.5 | 0.6% | May 29, 2023 | tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instanc... |
| CVE-2023-32072 | MEDIUM | 4.8 | 0.5% | May 29, 2023 | Tuleap is an open source tool for end to end traceability of application and system developments. Tuleap Community Editi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now