2023 CVE Vulnerabilities
31,267 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25134 | MEDIUM | 6.7 | 0.3% | Mar 21, 2023 | McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee spe... |
| CVE-2023-25686 | MEDIUM | 5.5 | 0.2% | Mar 21, 2023 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text ... |
| CVE-2023-27873 | MEDIUM | 6.5 | 0.8% | Mar 21, 2023 | IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using sp... |
| CVE-2023-25689 | MEDIUM | 5.3 | 0.7% | Mar 21, 2023 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse d... |
| CVE-2023-25687 | MEDIUM | 4.3 | 0.5% | Mar 21, 2023 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain ... |
| CVE-2023-27983 | MEDIUM | 5.3 | 0.4% | Mar 21, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could... |
| CVE-2023-27979 | MEDIUM | 6.5 | 0.2% | Mar 21, 2023 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the r... |
| CVE-2023-27977 | MEDIUM | 5.3 | 0.2% | Mar 21, 2023 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause acces... |
| CVE-2023-1154 | MEDIUM | 6.1 | 0.4% | Mar 21, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pacsrapor allows R... |
| CVE-2023-1542 | MEDIUM | 5.4 | 0.8% | Mar 21, 2023 | Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-1540 | MEDIUM | 5.3 | 0.6% | Mar 21, 2023 | Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-1539 | MEDIUM | 5.3 | 0.6% | Mar 21, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-1538 | MEDIUM | 5.3 | 0.6% | Mar 21, 2023 | Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6. |
| CVE-2023-1536 | MEDIUM | 5.4 | 0.5% | Mar 21, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7. |
| CVE-2023-1535 | MEDIUM | 5.4 | 0.5% | Mar 21, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7. |
| CVE-2023-1527 | MEDIUM | 5.4 | 0.5% | Mar 21, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0. |
| CVE-2023-28425 | MEDIUM | 5.5 | 55.0% | Mar 20, 2023 | Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticat... |
| CVE-2023-0681 | MEDIUM | 6.1 | 0.3% | Mar 20, 2023 | Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the abi... |
| CVE-2023-22288 | MEDIUM | 5.4 | 0.4% | Mar 20, 2023 | HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticate... |
| CVE-2023-1517 | MEDIUM | 4.8 | 0.4% | Mar 20, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.19. |
| CVE-2023-0937 | MEDIUM | 6.1 | 0.5% | Mar 20, 2023 | The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter ... |
| CVE-2023-0911 | MEDIUM | 6.5 | 0.7% | Mar 20, 2023 | The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to ... |
| CVE-2023-0890 | MEDIUM | 6.5 | 0.7% | Mar 20, 2023 | The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be di... |
| CVE-2023-0876 | MEDIUM | 6.1 | 0.7% | Mar 20, 2023 | The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to m... |
| CVE-2023-0370 | MEDIUM | 5.4 | 0.5% | Mar 20, 2023 | The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now