2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-22869 | MEDIUM | 5.5 | 0.2% | Apr 19, 2024 | IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a loca... |
| CVE-2023-49275 | MEDIUM | 6.5 | 0.9% | Apr 19, 2024 | Wazuh is a free and open source platform used for threat prevention, detection, and response. A NULL pointer dereference... |
| CVE-2023-6897 | MEDIUM | 4.3 | 0.4% | Apr 18, 2024 | The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an... |
| CVE-2023-6892 | MEDIUM | 5.4 | 0.3% | Apr 18, 2024 | The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_p... |
| CVE-2023-50885 | MEDIUM | 6.8 | 0.6% | Apr 18, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AGILELOGIX Store Locator... |
| CVE-2023-49768 | MEDIUM | 6.5 | 0.3% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormAssembly / Dre... |
| CVE-2023-3675 | MEDIUM | 6.5 | 0.5% | Apr 18, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Secomea GateManager (Web... |
| CVE-2023-41864 | MEDIUM | 4.3 | 0.2% | Apr 18, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Pepro Dev. Group PeproDev CF7 Database.This issue affects PeproDev CF... |
| CVE-2023-4509 | MEDIUM | 4.3 | 0.2% | Apr 18, 2024 | It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt. |
| CVE-2023-5407 | MEDIUM | 5.9 | 0.4% | Apr 17, 2024 | Controller denial of service due to improper handling of a specially crafted message received by the controller. See Ho... |
| CVE-2023-5406 | MEDIUM | 5.9 | 0.7% | Apr 17, 2024 | Server communication with a controller can lead to remote code execution using a specially crafted message from the cont... |
| CVE-2023-5405 | MEDIUM | 5.9 | 0.4% | Apr 17, 2024 | Server information leak for the CDA Server process memory can occur when an error is generated in response to a speciall... |
| CVE-2023-5398 | MEDIUM | 5.9 | 0.4% | Apr 17, 2024 | Server receiving a malformed message based on a list of IPs resulting in heap corruption causing a denial of service. Se... |
| CVE-2023-52645 | MEDIUM | 4.7 | 0.2% | Apr 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix race conditions with genpd ... |
| CVE-2023-6805 | MEDIUM | 6.4 | 0.3% | Apr 17, 2024 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is... |
| CVE-2023-52644 | MEDIUM | 6.3 | 0.2% | Apr 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: wifi: b43: Stop/wake correct queue in DMA Tx path w... |
| CVE-2023-52643 | MEDIUM | 5.5 | 0.2% | Apr 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: iio: core: fix memleak in iio_device_register_sysfs... |
| CVE-2023-25043 | MEDIUM | 4.3 | 0.5% | Apr 17, 2024 | Incorrect Authorization vulnerability in Supsystic Data Tables Generator.This issue affects Data Tables Generator: from ... |
| CVE-2023-45000 | MEDIUM | 5.3 | 0.4% | Apr 16, 2024 | Missing Authorization vulnerability in LiteSpeed Technologies LiteSpeed Cache.This issue affects LiteSpeed Cache: from n... |
| CVE-2023-40000 | MEDIUM | 6.1 | 54.9% | Apr 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technolo... |
| CVE-2023-45503 | MEDIUM | 5.3 | 0.9% | Apr 15, 2024 | SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denia... |
| CVE-2023-47626 | MEDIUM | 6.1 | 0.4% | Apr 15, 2024 | iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible... |
| CVE-2023-47622 | MEDIUM | 6.1 | 0.4% | Apr 15, 2024 | iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is... |
| CVE-2023-47123 | MEDIUM | 5.4 | 0.3% | Apr 15, 2024 | iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an... |
| CVE-2023-45808 | MEDIUM | 5.4 | 0.3% | Apr 15, 2024 | iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in t... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now