2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5773 | — | — | — | Nov 27, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-6136. Reason: This record is a reservatio... |
| CVE-2023-42363 | MEDIUM | 5.5 | 0.4% | Nov 27, 2023 | A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. |
| CVE-2023-32062 | MEDIUM | 4.3 | 0.5% | Nov 27, 2023 | OroPlatform is a package that assists system and user calendar management. Back-office users can access information from... |
| CVE-2023-49044 | CRITICAL | 9.8 | 1.4% | Nov 27, 2023 | Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid p... |
| CVE-2023-49030 | HIGH | 7.5 | 0.9% | Nov 27, 2023 | SQL Injection vulnerability in32ns KLive v.2019-1-19 and before allows a remote attacker to obtain sensitive information... |
| CVE-2023-48034 | MEDIUM | 6.1 | 0.2% | Nov 27, 2023 | An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless key... |
| CVE-2023-49316 | HIGH | 7.5 | 0.8% | Nov 27, 2023 | In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service. |
| CVE-2023-6329 | CRITICAL | 9.8 | 65.2% | Nov 27, 2023 | An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll c... |
| CVE-2023-5974 | CRITICAL | 9.8 | 3.1% | Nov 27, 2023 | The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parame... |
| CVE-2023-5958 | MEDIUM | 6.1 | 0.5% | Nov 27, 2023 | The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the bac... |
| CVE-2023-5942 | MEDIUM | 5.4 | 0.5% | Nov 27, 2023 | The Medialist WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2023-5906 | HIGH | 7.5 | 0.8% | Nov 27, 2023 | The Job Manager & Career WordPress plugin before 1.4.4 contains a vulnerability in the Directory Listings system, which ... |
| CVE-2023-5845 | MEDIUM | 5.3 | 0.6% | Nov 27, 2023 | The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthentic... |
| CVE-2023-5738 | MEDIUM | 5.4 | 0.4% | Nov 27, 2023 | The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could... |
| CVE-2023-5737 | MEDIUM | 4.3 | 0.5% | Nov 27, 2023 | The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users wit... |
| CVE-2023-5653 | MEDIUM | 6.1 | 0.5% | Nov 27, 2023 | The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers bef... |
| CVE-2023-5641 | MEDIUM | 6.1 | 0.4% | Nov 27, 2023 | The Martins Free & Easy SEO BackLink Link Building Network WordPress plugin before 1.2.30 does not sanitise and escape a... |
| CVE-2023-5620 | MEDIUM | 5.4 | 0.4% | Nov 27, 2023 | The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of th... |
| CVE-2023-5611 | MEDIUM | 5.3 | 0.3% | Nov 27, 2023 | The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting a... |
| CVE-2023-5604 | CRITICAL | 9.8 | 2.0% | Nov 27, 2023 | The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administra... |
| CVE-2023-5560 | MEDIUM | 6.1 | 0.5% | Nov 27, 2023 | The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputti... |
| CVE-2023-5559 | CRITICAL | 9.1 | 2.8% | Nov 27, 2023 | The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing... |
| CVE-2023-5525 | MEDIUM | 4.3 | 0.5% | Nov 27, 2023 | The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` A... |
| CVE-2023-5325 | MEDIUM | 6.1 | 0.5% | Nov 27, 2023 | The Woocommerce Vietnam Checkout WordPress plugin before 2.0.6 does not escape the custom shipping phone field no the ch... |
| CVE-2023-5239 | HIGH | 7.5 | 0.7% | Nov 27, 2023 | The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially un... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now