2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-35664 | MEDIUM | 5.5 | 0.1% | Sep 11, 2023 | In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. Th... |
| CVE-2023-35658 | HIGH | 8.8 | 0.2% | Sep 11, 2023 | In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible privilege escalation due to a use after free. This cou... |
| CVE-2023-4318 | MEDIUM | 4.3 | 0.2% | Sep 11, 2023 | The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers t... |
| CVE-2023-4314 | HIGH | 7.2 | 1.3% | Sep 11, 2023 | The wpDataTables WordPress plugin before 2.1.66 does not validate the "Serialized PHP array" input data before deseriali... |
| CVE-2023-4307 | MEDIUM | 4.3 | 0.2% | Sep 11, 2023 | The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, ... |
| CVE-2023-4294 | MEDIUM | 6.1 | 0.7% | Sep 11, 2023 | The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing a... |
| CVE-2023-4278 | HIGH | 7.5 | 3.5% | Sep 11, 2023 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registra... |
| CVE-2023-4270 | MEDIUM | 6.1 | 0.4% | Sep 11, 2023 | The Min Max Control WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting it back in th... |
| CVE-2023-4060 | MEDIUM | 4.8 | 0.4% | Sep 11, 2023 | The WP Adminify WordPress plugin before 3.1.6 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2023-4022 | MEDIUM | 4.8 | 0.4% | Sep 11, 2023 | The Herd Effects WordPress plugin before 5.2.3 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2023-41336 | MEDIUM | 6.5 | 0.5% | Sep 11, 2023 | ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could s... |
| CVE-2023-40946 | CRITICAL | 9.8 | 0.6% | Sep 11, 2023 | Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php. |
| CVE-2023-40945 | CRITICAL | 9.8 | 0.7% | Sep 11, 2023 | Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails... |
| CVE-2023-40944 | CRITICAL | 9.8 | 0.6% | Sep 11, 2023 | Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php. |
| CVE-2023-40150 | CRITICAL | 9.8 | 1.0% | Sep 11, 2023 | Softneta MedDream PACS does not perform an authentication check and performs some dangerous functionality, which could ... |
| CVE-2023-3510 | MEDIUM | 5.4 | 0.2% | Sep 11, 2023 | The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and i... |
| CVE-2023-3170 | MEDIUM | 4.8 | 0.4% | Sep 11, 2023 | The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, do... |
| CVE-2023-3169 | MEDIUM | 6.1 | 1.6% | Sep 11, 2023 | The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, do... |
| CVE-2023-39227 | HIGH | 7.5 | 0.3% | Sep 11, 2023 | Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers ... |
| CVE-2023-38256 | HIGH | 7.5 | 0.6% | Sep 11, 2023 | Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.... |
| CVE-2023-36497 | HIGH | 8.8 | 0.5% | Sep 11, 2023 | Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.... |
| CVE-2023-2705 | MEDIUM | 6.1 | 0.4% | Sep 11, 2023 | The gAppointments WordPress plugin before 1.10.0 does not sanitise and escape a parameter before outputting it back in t... |
| CVE-2023-41256 | CRITICAL | 9.1 | 0.7% | Sep 11, 2023 | Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3... |
| CVE-2023-41103 | MEDIUM | 5.4 | 0.4% | Sep 11, 2023 | Interact 7.9.79.5 allows stored Cross-site Scripting (XSS) attacks in several locations, allowing an attacker to store a... |
| CVE-2023-40032 | MEDIUM | 5.5 | 0.2% | Sep 11, 2023 | libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libv... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now