2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39975 | HIGH | 8.8 | 1.2% | Aug 16, 2023 | kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated... |
| CVE-2023-39115 | CRITICAL | 9.8 | 4.6% | Aug 16, 2023 | install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum... |
| CVE-2023-38904 | MEDIUM | 5.4 | 0.6% | Aug 16, 2023 | A Cross Site Scripting (XSS) vulnerability in Netlify CMS v.2.10.192 allows a remote attacker to execute arbitrary code ... |
| CVE-2023-33663 | CRITICAL | 9.8 | 0.5% | Aug 16, 2023 | In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can... |
| CVE-2023-32495 | HIGH | 7.8 | 0.2% | Aug 16, 2023 | Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability... |
| CVE-2023-32493 | CRITICAL | 9.8 | 0.7% | Aug 16, 2023 | Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker ... |
| CVE-2023-32492 | HIGH | 7.1 | 0.1% | Aug 16, 2023 | Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker ... |
| CVE-2023-32491 | MEDIUM | 6.5 | 0.3% | Aug 16, 2023 | Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A ... |
| CVE-2023-32490 | MEDIUM | 6.7 | 0.2% | Aug 16, 2023 | Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attack... |
| CVE-2023-32489 | MEDIUM | 6.7 | 0.2% | Aug 16, 2023 | Dell PowerScale OneFS 8.2x -9.5x contains a privilege escalation vulnerability. A local attacker with high privileges c... |
| CVE-2023-32488 | MEDIUM | 4.3 | 0.3% | Aug 16, 2023 | Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacke... |
| CVE-2023-32487 | HIGH | 7.8 | 0.2% | Aug 16, 2023 | Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attack... |
| CVE-2023-32486 | HIGH | 7.8 | 0.1% | Aug 16, 2023 | Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could ... |
| CVE-2023-32494 | MEDIUM | 6.7 | 0.2% | Aug 16, 2023 | Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local pr... |
| CVE-2023-4381 | MEDIUM | 4.3 | 0.4% | Aug 16, 2023 | Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
| CVE-2023-2272 | MEDIUM | 6.1 | 0.9% | Aug 16, 2023 | The Tiempo.com WordPress plugin through 0.1.2 does not sanitise and escape the page parameter before outputting it back ... |
| CVE-2023-2271 | MEDIUM | 4.3 | 0.3% | Aug 16, 2023 | The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when deleting its shortcode, which could allow at... |
| CVE-2023-2254 | MEDIUM | 4.8 | 0.4% | Aug 16, 2023 | The Ko-fi Button WordPress plugin before 1.3.3 does not properly some of its settings, which could allow high-privilege ... |
| CVE-2023-2225 | MEDIUM | 4.8 | 0.5% | Aug 16, 2023 | The SEO ALert WordPress plugin through 1.59 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2023-2123 | MEDIUM | 6.1 | 1.2% | Aug 16, 2023 | The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it ... |
| CVE-2023-2122 | MEDIUM | 6.1 | 0.9% | Aug 16, 2023 | The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter ... |
| CVE-2023-1977 | HIGH | 8.8 | 0.8% | Aug 16, 2023 | The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for... |
| CVE-2023-1465 | MEDIUM | 6.1 | 0.5% | Aug 16, 2023 | The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, lea... |
| CVE-2023-1110 | MEDIUM | 5.4 | 0.5% | Aug 16, 2023 | The Yellow Yard Searchbar WordPress plugin before 2.8.12 does not validate and escape some of its shortcode attributes b... |
| CVE-2023-0579 | HIGH | 8.8 | 0.9% | Aug 16, 2023 | The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now