2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27929 | MEDIUM | 5.5 | 0.2% | May 8, 2023 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4... |
| CVE-2023-23542 | MEDIUM | 5.5 | 0.3% | May 8, 2023 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura... |
| CVE-2023-23538 | MEDIUM | 5.5 | 0.2% | May 8, 2023 | A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. An a... |
| CVE-2023-23537 | MEDIUM | 5.5 | 0.2% | May 8, 2023 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura... |
| CVE-2023-23535 | MEDIUM | 5.5 | 0.2% | May 8, 2023 | The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16... |
| CVE-2023-23534 | MEDIUM | 5.5 | 0.3% | May 8, 2023 | The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5. Processin... |
| CVE-2023-23533 | MEDIUM | 5.5 | 0.3% | May 8, 2023 | A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. An a... |
| CVE-2023-23528 | MEDIUM | 6.5 | 0.3% | May 8, 2023 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 16.4, iOS 16.4 and iPadOS... |
| CVE-2023-23527 | MEDIUM | 5.5 | 0.3% | May 8, 2023 | The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS... |
| CVE-2023-23494 | MEDIUM | 5.3 | 0.6% | May 8, 2023 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. A user i... |
| CVE-2023-30860 | MEDIUM | 5.4 | 0.7% | May 8, 2023 | WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule... |
| CVE-2023-1979 | MEDIUM | 6.5 | 0.4% | May 8, 2023 | The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password... |
| CVE-2023-30019 | MEDIUM | 5.3 | 2.2% | May 8, 2023 | imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL para... |
| CVE-2023-28493 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes NewsMag theme <= 2.4.4 versions. |
| CVE-2023-24408 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart pl... |
| CVE-2023-22791 | MEDIUM | 4.8 | 0.2% | May 8, 2023 | A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a spec... |
| CVE-2023-1905 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page short... |
| CVE-2023-1806 | MEDIUM | 6.1 | 0.5% | May 8, 2023 | The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outp... |
| CVE-2023-1660 | MEDIUM | 6.1 | 0.3% | May 8, 2023 | The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing... |
| CVE-2023-1651 | MEDIUM | 5.4 | 0.2% | May 8, 2023 | The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in the AJAX action responsible to upda... |
| CVE-2023-1649 | MEDIUM | 4.8 | 0.4% | May 8, 2023 | The AI ChatBot WordPress plugin before 4.5.1 does not sanitise and escape numerous of its settings, which could allow hi... |
| CVE-2023-1011 | MEDIUM | 6.1 | 0.2% | May 8, 2023 | The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the das... |
| CVE-2023-0948 | MEDIUM | 6.1 | 0.9% | May 8, 2023 | The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in att... |
| CVE-2023-0894 | MEDIUM | 4.8 | 0.4% | May 8, 2023 | The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settin... |
| CVE-2023-0544 | MEDIUM | 4.8 | 0.4% | May 8, 2023 | The WP Login Box WordPress plugin through 2.0.2 does not sanitise and escape some of its settings, which could allow hig... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now