2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34477 | CRITICAL | 9.8 | 0.5% | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. |
| CVE-2023-34476 | CRITICAL | 9.8 | 0.5% | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. |
| CVE-2023-32783 | HIGH | 7.5 | 3.2% | Aug 7, 2023 | The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by cre... |
| CVE-2023-23758 | CRITICAL | 9.8 | 0.5% | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. |
| CVE-2023-23757 | CRITICAL | 9.8 | 0.5% | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. |
| CVE-2023-3671 | MEDIUM | 6.1 | 0.4% | Aug 7, 2023 | The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters... |
| CVE-2023-3650 | MEDIUM | 4.8 | 0.6% | Aug 7, 2023 | The Bubble Menu WordPress plugin before 3.0.5 does not sanitize and escape some of its settings, which could allow high-... |
| CVE-2023-3575 | MEDIUM | 5.4 | 0.5% | Aug 7, 2023 | The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which c... |
| CVE-2023-3524 | MEDIUM | 6.1 | 0.5% | Aug 7, 2023 | The WPCode WordPress plugin before 2.0.13.1 does not escape generated URLs before outputting them in attributes, leading... |
| CVE-2023-3492 | MEDIUM | 6.8 | 0.3% | Aug 7, 2023 | The WP Shopping Pages WordPress plugin through 1.14 does not have CSRF check in some places, and is missing sanitisation... |
| CVE-2023-3365 | HIGH | 8.1 | 0.6% | Aug 7, 2023 | The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting ship... |
| CVE-2023-2843 | HIGH | 8.8 | 0.7% | Aug 7, 2023 | The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parame... |
| CVE-2023-27373 | MEDIUM | 5.5 | 0.2% | Aug 7, 2023 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attack... |
| CVE-2023-0604 | MEDIUM | 5.4 | 0.4% | Aug 7, 2023 | The WP Food Manager WordPress plugin before 1.0.4 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2023-4205 | — | — | — | Aug 7, 2023 | Rejected reason: This was deemed as a false positive both by the reporter and upstream kernel. |
| CVE-2023-4194 | MEDIUM | 5.5 | 0.3% | Aug 7, 2023 | A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filt... |
| CVE-2023-4147 | HIGH | 7.8 | 0.6% | Aug 7, 2023 | A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID... |
| CVE-2023-36220 | HIGH | 7.2 | 2.9% | Aug 7, 2023 | Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary ... |
| CVE-2023-3896 | HIGH | 7.8 | 0.4% | Aug 7, 2023 | Divide By Zero in vim/vim from 9.0.1367-1 to 9.0.1367-3 |
| CVE-2023-38392 | MEDIUM | 6.1 | 0.4% | Aug 7, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.9 ve... |
| CVE-2023-32090 | CRITICAL | 9.8 | 0.5% | Aug 7, 2023 | Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials |
| CVE-2023-0426 | HIGH | 7.5 | 0.4% | Aug 7, 2023 | ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported... |
| CVE-2023-0425 | HIGH | 7.5 | 0.4% | Aug 7, 2023 | ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported... |
| CVE-2023-39903 | MEDIUM | 5 | 0.1% | Aug 7, 2023 | An issue was discovered in Fujitsu Software Infrastructure Manager (ISM) before 2.8.0.061. The ismsnap component (in thi... |
| CVE-2023-20818 | MEDIUM | 4.4 | 0.1% | Aug 7, 2023 | In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local infor... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now