2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6786 | MEDIUM | 6.1 | 0.5% | May 15, 2025 | The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirectin... |
| CVE-2023-6783 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The WolfNet IDX for WordPress plugin through 1.19.1 does not sanitise and escape some of its settings, which could allow... |
| CVE-2023-6541 | MEDIUM | 6.1 | 0.3% | May 15, 2025 | The Allow SVG WordPress plugin before 1.2.0 does not sanitize uploaded SVG files, which could allow users with a role as... |
| CVE-2023-6030 | MEDIUM | 5.4 | 0.7% | May 15, 2025 | The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in ... |
| CVE-2023-5934 | HIGH | 7.3 | 0.2% | May 15, 2025 | The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when ... |
| CVE-2023-5932 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.14 does not sanitise and escape a paramete... |
| CVE-2023-5529 | MEDIUM | 4.8 | 0.3% | May 15, 2025 | The Advanced Page Visit Counter WordPress plugin before 8.0.6 does not sanitise and escape some of its settings, which ... |
| CVE-2023-2334 | MEDIUM | 5.4 | 0.2% | May 15, 2025 | The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress ... |
| CVE-2023-53146 | MEDIUM | 5.5 | 0.1% | May 14, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: dw2102: Fix null-ptr-deref in dw2102_i2c_tra... |
| CVE-2023-31359 | HIGH | 7.8 | 0.1% | May 13, 2025 | Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, pote... |
| CVE-2023-31358 | HIGH | 7.8 | 0.1% | May 13, 2025 | A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, pote... |
| CVE-2023-49641 | CRITICAL | 9.8 | 0.4% | May 13, 2025 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter ... |
| CVE-2023-34732 | MEDIUM | 5.4 | 0.2% | May 12, 2025 | An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c a... |
| CVE-2023-53145 | HIGH | 7.8 | 0.2% | May 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btsdio: fix use after free bug in btsdio... |
| CVE-2023-31585 | CRITICAL | 9.8 | 0.7% | May 8, 2025 | Grocery-CMS-PHP-Restful-API v1.3 is vulnerable to File Upload via /admin/add-category.php. |
| CVE-2023-51328 | MEDIUM | 5.4 | 0.3% | May 8, 2025 | PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "c_name, n... |
| CVE-2023-51295 | MEDIUM | 6.5 | 0.3% | May 8, 2025 | PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin... |
| CVE-2023-7303 | MEDIUM | 5.1 | 0.3% | May 7, 2025 | A vulnerability, which was classified as problematic, was found in q2apro q2apro-on-site-notifications up to 1.4.6. This... |
| CVE-2023-33770 | MEDIUM | 5.1 | 0.2% | May 6, 2025 | Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at ... |
| CVE-2023-46716 | — | — | — | May 6, 2025 | Rejected reason: Not used |
| CVE-2023-53144 | MEDIUM | 5.5 | 0.1% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: erofs: fix wrong kunmap when using LZMA on HIGHMEM ... |
| CVE-2023-53143 | MEDIUM | 5.5 | 0.2% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix another off-by-one fsmap error on 1k bloc... |
| CVE-2023-53142 | HIGH | 7.8 | 0.2% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: ice: copy last block omitted in ice_get_module_eepr... |
| CVE-2023-53141 | MEDIUM | 5.5 | 0.1% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: ila: do not generate empty messages in ila_xlat_nl_... |
| CVE-2023-53140 | MEDIUM | 5.5 | 0.1% | May 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: core: Remove the /proc/scsi/${proc_name} dire... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now