2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3408 | MEDIUM | 4.3 | 0.2% | Aug 17, 2024 | The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This... |
| CVE-2023-4730 | MEDIUM | 5.3 | 0.5% | Aug 17, 2024 | The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ... |
| CVE-2023-4604 | MEDIUM | 6.1 | 0.3% | Aug 17, 2024 | The Slideshow, Image Slider by 2J plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post’ pa... |
| CVE-2023-4507 | MEDIUM | 6.1 | 0.3% | Aug 17, 2024 | The Admission AppManager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter in v... |
| CVE-2023-4027 | MEDIUM | 5.3 | 0.4% | Aug 17, 2024 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2023-4025 | MEDIUM | 5.3 | 0.4% | Aug 17, 2024 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2023-4024 | MEDIUM | 5.3 | 0.4% | Aug 17, 2024 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2023-1604 | MEDIUM | 4.7 | 0.2% | Aug 17, 2024 | The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. ... |
| CVE-2023-47728 | MEDIUM | 6.5 | 0.5% | Aug 16, 2024 | IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could al... |
| CVE-2023-7049 | MEDIUM | 4.3 | 0.4% | Aug 16, 2024 | The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versio... |
| CVE-2023-50315 | MEDIUM | 5.9 | 0.3% | Aug 14, 2024 | IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing atta... |
| CVE-2023-48361 | MEDIUM | 4.6 | 0.2% | Aug 14, 2024 | Improper initialization in firmware for some Intel(R) CSME may allow a privileged user to potentially enable information... |
| CVE-2023-43747 | MEDIUM | 6.7 | 0.1% | Aug 14, 2024 | Incorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 ma... |
| CVE-2023-43489 | MEDIUM | 5.5 | 0.1% | Aug 14, 2024 | Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to poten... |
| CVE-2023-40067 | MEDIUM | 5.7 | 0.2% | Aug 14, 2024 | Unchecked return value in firmware for some Intel(R) CSME may allow an unauthenticated user to potentially enable escala... |
| CVE-2023-38655 | MEDIUM | 6.9 | 0.5% | Aug 14, 2024 | Improper buffer restrictions in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privilege... |
| CVE-2023-35123 | MEDIUM | 5.9 | 0.4% | Aug 14, 2024 | Uncaught exception in OpenBMC Firmware for some Intel(R) Server Platforms before versions egs-1.14-0, bhs-0.27 may allow... |
| CVE-2023-34424 | MEDIUM | 6.7 | 0.2% | Aug 14, 2024 | Improper input validation in firmware for some Intel(R) CSME may allow a privileged user to potentially enable denial of... |
| CVE-2023-31366 | MEDIUM | 5.5 | 0.1% | Aug 13, 2024 | Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially res... |
| CVE-2023-31356 | MEDIUM | 4.4 | 0.2% | Aug 13, 2024 | Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, pote... |
| CVE-2023-31341 | MEDIUM | 5.5 | 0.1% | Aug 13, 2024 | Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacke... |
| CVE-2023-31339 | MEDIUM | 5.8 | 0.2% | Aug 13, 2024 | Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged ... |
| CVE-2023-31310 | MEDIUM | 5 | 0.1% | Aug 13, 2024 | Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed ... |
| CVE-2023-31307 | MEDIUM | 4.4 | 0.2% | Aug 13, 2024 | Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-o... |
| CVE-2023-20584 | MEDIUM | 6 | 0.2% | Aug 13, 2024 | IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an att... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now