2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4281 | MEDIUM | 5.3 | 0.6% | Sep 25, 2023 | This Activity Log WordPress plugin before 2.8.8 retrieves client IP addresses from potentially untrusted headers, allowi... |
| CVE-2023-4238 | HIGH | 7.2 | 1.3% | Sep 25, 2023 | The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could all... |
| CVE-2023-4148 | MEDIUM | 6.1 | 0.8% | Sep 25, 2023 | The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputti... |
| CVE-2023-43382 | HIGH | 8.8 | 1.5% | Sep 25, 2023 | Directory Traversal vulnerability in itechyou dreamer CMS v.4.1.3 allows a remote attacker to execute arbitrary code via... |
| CVE-2023-43339 | MEDIUM | 6.1 | 0.6% | Sep 25, 2023 | Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via... |
| CVE-2023-43141 | CRITICAL | 9.8 | 0.7% | Sep 25, 2023 | TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control. |
| CVE-2023-40163 | CRITICAL | 9.8 | 1.0% | Sep 25, 2023 | An out-of-bounds write vulnerability exists in the allocate_buffer_for_jpeg_decoding functionality of Accusoft ImageGear... |
| CVE-2023-3664 | HIGH | 7.2 | 0.6% | Sep 25, 2023 | The FileOrganizer WordPress plugin through 1.0.2 does not restrict functionality on multisite instances, allowing site a... |
| CVE-2023-3550 | HIGH | 7.3 | 1.2% | Sep 25, 2023 | Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML f... |
| CVE-2023-3547 | HIGH | 8.8 | 0.3% | Sep 25, 2023 | The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly check nonce values in several action... |
| CVE-2023-3226 | MEDIUM | 4.8 | 0.4% | Sep 25, 2023 | The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2023-39453 | CRITICAL | 9.8 | 1.2% | Sep 25, 2023 | A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially cra... |
| CVE-2023-35002 | CRITICAL | 9.8 | 1.3% | Sep 25, 2023 | A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially... |
| CVE-2023-32653 | HIGH | 8.8 | 1.0% | Sep 25, 2023 | An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A spe... |
| CVE-2023-32614 | CRITICAL | 9.8 | 0.7% | Sep 25, 2023 | A heap-based buffer overflow vulnerability exists in the create_png_object functionality of Accusoft ImageGear 20.1. A s... |
| CVE-2023-32284 | CRITICAL | 9.8 | 0.8% | Sep 25, 2023 | An out-of-bounds write vulnerability exists in the tiff_planar_adobe functionality of Accusoft ImageGear 20.1. A special... |
| CVE-2023-28393 | HIGH | 8.8 | 0.5% | Sep 25, 2023 | A stack-based buffer overflow vulnerability exists in the tif_processing_dng_channel_count functionality of Accusoft Ima... |
| CVE-2023-23567 | HIGH | 8.8 | 1.0% | Sep 25, 2023 | A heap-based buffer overflow vulnerability exists in the CreateDIBfromPict functionality of Accusoft ImageGear 20.1. A s... |
| CVE-2023-0633 | HIGH | 7.8 | 0.3% | Sep 25, 2023 | In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (... |
| CVE-2023-0627 | HIGH | 7.8 | 0.2% | Sep 25, 2023 | Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privi... |
| CVE-2023-0626 | CRITICAL | 9.8 | 0.7% | Sep 25, 2023 | Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker ... |
| CVE-2023-0625 | CRITICAL | 9.8 | 0.7% | Sep 25, 2023 | Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects ... |
| CVE-2023-43456 | MEDIUM | 5.4 | 0.7% | Sep 25, 2023 | Cross Site Scripting vulnerability in Service Provider Management System v.1.0 allows a remote attacker to execute arbit... |
| CVE-2023-43131 | CRITICAL | 9.8 | 0.9% | Sep 25, 2023 | General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow. |
| CVE-2023-43256 | MEDIUM | 6.5 | 0.7% | Sep 25, 2023 | A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now