2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1304 | HIGH | 8.8 | 1.1% | Mar 21, 2023 | An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perfo... |
| CVE-2023-25923 | HIGH | 7.5 | 0.7% | Mar 21, 2023 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that... |
| CVE-2023-27874 | HIGH | 8.8 | 1.3% | Mar 21, 2023 | IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot... |
| CVE-2023-27871 | HIGH | 7.5 | 0.9% | Mar 21, 2023 | IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, u... |
| CVE-2023-27842 | HIGH | 8.8 | 2.4% | Mar 21, 2023 | Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execut... |
| CVE-2023-1314 | HIGH | 7.8 | 0.3% | Mar 21, 2023 | A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a l... |
| CVE-2023-27984 | HIGH | 8.8 | 0.6% | Mar 21, 2023 | A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, pote... |
| CVE-2023-1545 | HIGH | 7.5 | 8.4% | Mar 21, 2023 | SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. |
| CVE-2023-27981 | HIGH | 8.8 | 0.7% | Mar 21, 2023 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could ... |
| CVE-2023-27978 | HIGH | 7.8 | 6.5% | Mar 21, 2023 | A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpreta... |
| CVE-2023-1462 | HIGH | 8.8 | 0.7% | Mar 21, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Aut... |
| CVE-2023-27982 | HIGH | 8.8 | 0.4% | Mar 21, 2023 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manip... |
| CVE-2023-27980 | HIGH | 8.8 | 0.9% | Mar 21, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could... |
| CVE-2023-1543 | HIGH | 8.8 | 0.8% | Mar 21, 2023 | Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-27578 | HIGH | 7.5 | 0.8% | Mar 20, 2023 | Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05... |
| CVE-2023-27586 | HIGH | 7.1 | 0.7% | Mar 20, 2023 | CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to e... |
| CVE-2023-0940 | HIGH | 8.8 | 0.8% | Mar 20, 2023 | The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not imple... |
| CVE-2023-0875 | HIGH | 8.8 | 0.9% | Mar 20, 2023 | The WP Meta SEO WordPress plugin before 4.5.3 does not properly sanitize and escape inputs into SQL queries, leading to ... |
| CVE-2023-0865 | HIGH | 8.8 | 1.2% | Mar 20, 2023 | The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to ... |
| CVE-2023-0631 | HIGH | 8.8 | 60.5% | Mar 20, 2023 | The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that conc... |
| CVE-2023-0630 | HIGH | 8.8 | 5.1% | Mar 20, 2023 | The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that conca... |
| CVE-2023-0340 | HIGH | 8.8 | 1.0% | Mar 20, 2023 | The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which coul... |
| CVE-2023-28118 | HIGH | 7.5 | 1.0% | Mar 20, 2023 | kaml provides YAML support for kotlinx.serialization. Prior to version 0.53.0, applications that use kaml to parse untru... |
| CVE-2023-26513 | HIGH | 7.5 | 1.5% | Mar 20, 2023 | Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache S... |
| CVE-2023-23721 | HIGH | 8.8 | 0.3% | Mar 20, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in David Gwyer Admin Log plugin <= 1.50 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now