2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32189 | MEDIUM | 6.4 | 0.1% | Oct 16, 2024 | Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys |
| CVE-2023-7296 | MEDIUM | 6.4 | 0.3% | Oct 16, 2024 | The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewe... |
| CVE-2023-7295 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in ver... |
| CVE-2023-22649 | MEDIUM | 6.5 | 1.9% | Oct 16, 2024 | A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Au... |
| CVE-2023-7294 | MEDIUM | 6.5 | 0.3% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due t... |
| CVE-2023-7293 | MEDIUM | 4.3 | 0.2% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a... |
| CVE-2023-7292 | MEDIUM | 4.3 | 0.3% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal ... |
| CVE-2023-7290 | MEDIUM | 4.3 | 0.2% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a... |
| CVE-2023-7289 | MEDIUM | 4.3 | 0.3% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a... |
| CVE-2023-7288 | MEDIUM | 4.3 | 0.3% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due t... |
| CVE-2023-7287 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellati... |
| CVE-2023-7286 | MEDIUM | 6.5 | 0.4% | Oct 16, 2024 | The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and ... |
| CVE-2023-31493 | MEDIUM | 6.6 | 0.7% | Oct 15, 2024 | RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in langua... |
| CVE-2023-42133 | MEDIUM | 6.7 | 0.2% | Oct 11, 2024 | PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must hav... |
| CVE-2023-45872 | MEDIUM | 6.5 | 0.4% | Oct 9, 2024 | An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image wh... |
| CVE-2023-45361 | MEDIUM | 6.1 | 0.3% | Oct 9, 2024 | An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40... |
| CVE-2023-45359 | MEDIUM | 6.5 | 0.3% | Oct 9, 2024 | An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-to... |
| CVE-2023-26771 | MEDIUM | 6.5 | 0.3% | Oct 4, 2024 | Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading... |
| CVE-2023-7273 | MEDIUM | 6.8 | 0.2% | Oct 1, 2024 | Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has ... |
| CVE-2023-46175 | MEDIUM | 4.9 | 0.3% | Sep 26, 2024 | IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which... |
| CVE-2023-52950 | MEDIUM | 5.3 | 0.1% | Sep 26, 2024 | Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent befor... |
| CVE-2023-52949 | MEDIUM | 5.5 | 0.2% | Sep 26, 2024 | Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for... |
| CVE-2023-52948 | MEDIUM | 5 | 0.1% | Sep 26, 2024 | Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agen... |
| CVE-2023-51157 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obt... |
| CVE-2023-26688 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now