2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2959 | HIGH | 7.5 | 0.5% | Jul 17, 2023 | Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Pr... |
| CVE-2023-2701 | MEDIUM | 6.1 | 0.5% | Jul 17, 2023 | The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, lea... |
| CVE-2023-2636 | HIGH | 8.8 | 3.2% | Jul 17, 2023 | The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a S... |
| CVE-2023-2579 | MEDIUM | 5.4 | 1.1% | Jul 17, 2023 | The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow use... |
| CVE-2023-2330 | HIGH | 8.8 | 0.3% | Jul 17, 2023 | The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access ... |
| CVE-2023-2329 | HIGH | 8.8 | 0.3% | Jul 17, 2023 | The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access C... |
| CVE-2023-2143 | MEDIUM | 5.4 | 0.3% | Jul 17, 2023 | The Enable SVG, WebP & ICO Upload WordPress plugin through 1.0.3 does not sanitize SVG file contents, leading to a Cross... |
| CVE-2023-1893 | MEDIUM | 6.1 | 0.7% | Jul 17, 2023 | The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the... |
| CVE-2023-0439 | MEDIUM | 5.4 | 0.3% | Jul 17, 2023 | The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripti... |
| CVE-2023-2912 | HIGH | 7.5 | 0.5% | Jul 17, 2023 | Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction. |
| CVE-2023-27424 | HIGH | 8.8 | 0.2% | Jul 17, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Korol Yuriy aka Shra Inactive User Deleter plugin <= 1.59 versions. |
| CVE-2023-34036 | MEDIUM | 5.3 | 0.4% | Jul 17, 2023 | Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious f... |
| CVE-2023-27606 | HIGH | 8.8 | 0.2% | Jul 17, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Sajjad Hossain WP Reroute Email plugin <= 1.4.6 versions. |
| CVE-2023-23719 | HIGH | 8.8 | 0.2% | Jul 17, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Premmerce plugin <= 1.3.17 versions. |
| CVE-2023-23646 | HIGH | 8.8 | 0.3% | Jul 17, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions. |
| CVE-2023-22672 | HIGH | 8.8 | 0.3% | Jul 17, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.2 vers... |
| CVE-2023-26512 | CRITICAL | 9.8 | 1.0% | Jul 17, 2023 | CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.... |
| CVE-2023-3700 | MEDIUM | 4.3 | 0.4% | Jul 17, 2023 | Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| CVE-2023-2760 | HIGH | 7.6 | 0.4% | Jul 17, 2023 | An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version... |
| CVE-2023-2759 | HIGH | 8.8 | 0.5% | Jul 17, 2023 | A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user t... |
| CVE-2023-3696 | CRITICAL | 9.8 | 1.0% | Jul 17, 2023 | Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4. |
| CVE-2023-3695 | CRITICAL | 9.8 | 0.5% | Jul 17, 2023 | A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. Affected is an un... |
| CVE-2023-35012 | MEDIUM | 6.7 | 0.2% | Jul 17, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a... |
| CVE-2023-3694 | CRITICAL | 9.8 | 0.7% | Jul 17, 2023 | A vulnerability, which was classified as critical, has been found in SourceCodester/projectworlds House Rental and Prope... |
| CVE-2023-35901 | MEDIUM | 5.3 | 0.4% | Jul 17, 2023 | IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now