2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2803 | MEDIUM | 6.1 | 0.5% | Aug 14, 2023 | The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape a parameter before ou... |
| CVE-2023-2802 | MEDIUM | 4.8 | 0.4% | Aug 14, 2023 | The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape some of its settings,... |
| CVE-2023-2606 | MEDIUM | 4.8 | 2.0% | Aug 14, 2023 | The WP Brutal AI WordPress plugin before 2.06 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2023-39908 | HIGH | 7.5 | 0.5% | Aug 14, 2023 | The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations... |
| CVE-2023-39293 | CRITICAL | 9.8 | 1.4% | Aug 14, 2023 | A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which co... |
| CVE-2023-39292 | CRITICAL | 9.8 | 0.5% | Aug 14, 2023 | A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could ... |
| CVE-2023-29468 | CRITICAL | 9.8 | 10.1% | Aug 14, 2023 | The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_... |
| CVE-2023-28483 | HIGH | 8.8 | 0.7% | Aug 14, 2023 | An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write... |
| CVE-2023-28482 | MEDIUM | 6.5 | 0.5% | Aug 14, 2023 | An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are a... |
| CVE-2023-28481 | HIGH | 8.8 | 0.6% | Aug 14, 2023 | An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any... |
| CVE-2023-28480 | MEDIUM | 6.5 | 0.5% | Aug 14, 2023 | An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined ... |
| CVE-2023-40360 | MEDIUM | 5.5 | 0.4% | Aug 14, 2023 | QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whe... |
| CVE-2023-40312 | MEDIUM | 5.2 | 0.6% | Aug 14, 2023 | Multiple reflected XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versi... |
| CVE-2023-40311 | MEDIUM | 4.8 | 0.7% | Aug 14, 2023 | Multiple stored XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versions... |
| CVE-2023-38741 | HIGH | 7.5 | 0.8% | Aug 14, 2023 | IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement ... |
| CVE-2023-38721 | HIGH | 7.8 | 0.2% | Aug 14, 2023 | The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. ... |
| CVE-2023-32748 | CRITICAL | 9.8 | 0.9% | Aug 14, 2023 | The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated a... |
| CVE-2023-0872 | HIGH | 8 | 3.0% | Aug 14, 2023 | The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple pl... |
| CVE-2023-40359 | CRITICAL | 9.8 | 0.7% | Aug 14, 2023 | xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither... |
| CVE-2023-40354 | MEDIUM | 6.5 | 0.3% | Aug 14, 2023 | An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create ser... |
| CVE-2023-33013 | HIGH | 8.8 | 1.4% | Aug 14, 2023 | A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)... |
| CVE-2023-28768 | MEDIUM | 6.5 | 0.3% | Aug 14, 2023 | Improper frame handling in the Zyxel XGS2220-30 firmware version V4.80(ABXN.1), XMG1930-30 firmware version V4.80(ACAR.1... |
| CVE-2023-4322 | CRITICAL | 9.8 | 0.9% | Aug 14, 2023 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. |
| CVE-2023-31041 | HIGH | 7.5 | 0.3% | Aug 14, 2023 | An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information c... |
| CVE-2023-30754 | MEDIUM | 6.1 | 0.4% | Aug 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt plugin... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now