2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-44396 | MEDIUM | 5.4 | 0.4% | Apr 15, 2024 | iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.1... |
| CVE-2023-43790 | MEDIUM | 5.4 | 0.4% | Apr 15, 2024 | iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fie... |
| CVE-2023-38511 | MEDIUM | 4.3 | 0.7% | Apr 15, 2024 | iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure... |
| CVE-2023-52144 | MEDIUM | 5.5 | 0.4% | Apr 15, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Ma... |
| CVE-2023-7201 | MEDIUM | 6.5 | 0.6% | Apr 15, 2024 | The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high ... |
| CVE-2023-6067 | MEDIUM | 5.4 | 0.4% | Apr 15, 2024 | The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes ... |
| CVE-2023-6494 | MEDIUM | 4.4 | 0.3% | Apr 13, 2024 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set... |
| CVE-2023-52211 | MEDIUM | 5.3 | 0.4% | Apr 12, 2024 | Missing Authorization vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.0... |
| CVE-2023-51499 | MEDIUM | 4.3 | 0.4% | Apr 12, 2024 | Missing Authorization vulnerability in WooCommerce WooCommerce Shipping Per Product.This issue affects WooCommerce Shipp... |
| CVE-2023-47714 | MEDIUM | 5.4 | 0.3% | Apr 12, 2024 | IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scri... |
| CVE-2023-44856 | MEDIUM | 6.1 | 0.5% | Apr 12, 2024 | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitra... |
| CVE-2023-44855 | MEDIUM | 6.5 | 0.5% | Apr 12, 2024 | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrar... |
| CVE-2023-44854 | MEDIUM | 6.1 | 0.5% | Apr 12, 2024 | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitra... |
| CVE-2023-44853 | MEDIUM | 4.8 | 0.3% | Apr 12, 2024 | \An issue was discovered in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a cr... |
| CVE-2023-50307 | MEDIUM | 5.4 | 0.3% | Apr 12, 2024 | IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site sc... |
| CVE-2023-45186 | MEDIUM | 5.4 | 0.3% | Apr 12, 2024 | IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site sc... |
| CVE-2023-6678 | MEDIUM | 6.5 | 0.6% | Apr 12, 2024 | An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 1... |
| CVE-2023-6489 | MEDIUM | 6.5 | 0.6% | Apr 12, 2024 | A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 ... |
| CVE-2023-48865 | MEDIUM | 6.5 | 0.6% | Apr 11, 2024 | An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter ... |
| CVE-2023-32295 | MEDIUM | 6.3 | 0.4% | Apr 11, 2024 | Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a ... |
| CVE-2023-32228 | MEDIUM | 4.6 | 0.2% | Apr 11, 2024 | A firmware bug which may lead to misinterpretation of data in the AMC2-4WCF and AMC2-2WCF allowing an adversary to grant... |
| CVE-2023-6257 | MEDIUM | 4.3 | 0.4% | Apr 11, 2024 | The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users a... |
| CVE-2023-51141 | MEDIUM | 6.5 | 0.8% | Apr 11, 2024 | An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentic... |
| CVE-2023-27607 | MEDIUM | 5.4 | 0.4% | Apr 11, 2024 | Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Reward... |
| CVE-2023-6385 | MEDIUM | 4.3 | 0.2% | Apr 10, 2024 | The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now