2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3118 | MEDIUM | 6.1 | 0.5% | Jul 10, 2023 | The Export All URLs WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting them back in ... |
| CVE-2023-3077 | CRITICAL | 9.8 | 5.3% | Jul 10, 2023 | The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement... |
| CVE-2023-3076 | CRITICAL | 9.8 | 1.7% | Jul 10, 2023 | The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of thei... |
| CVE-2023-3045 | CRITICAL | 9.8 | 0.8% | Jul 10, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tise Technology Pa... |
| CVE-2023-37392 | HIGH | 8.8 | 0.3% | Jul 10, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Deepak Anand WP Dummy Content Generator plugin <= 2.3.0 versions. |
| CVE-2023-37153 | MEDIUM | 6.1 | 0.6% | Jul 10, 2023 | KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation fe... |
| CVE-2023-37152 | CRITICAL | 9.8 | 1.7% | Jul 10, 2023 | Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the admi... |
| CVE-2023-37151 | — | — | — | Jul 10, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2246. Reason: This candidate is a reservation du... |
| CVE-2023-37150 | MEDIUM | 6.1 | 0.5% | Jul 10, 2023 | Sourcecodester Online Pizza Ordering System v1.0 has a Cross-site scripting (XSS) vulnerability in "/admin/index.php?pag... |
| CVE-2023-36935 | — | — | — | Jul 10, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-36691 | HIGH | 8.8 | 0.3% | Jul 10, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Albert Peschar WebwinkelKeur plugin <= 3.24 versions. |
| CVE-2023-36376 | MEDIUM | 4.8 | 0.5% | Jul 10, 2023 | Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scr... |
| CVE-2023-36360 | — | — | — | Jul 10, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-35912 | HIGH | 8.8 | 0.3% | Jul 10, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Potent Donations for WooCommerce plugin <= 1.1.9 versions. |
| CVE-2023-35887 | MEDIUM | 4.3 | 1.0% | Jul 10, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In ... |
| CVE-2023-35699 | MEDIUM | 4.6 | 0.2% | Jul 10, 2023 | Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device t... |
| CVE-2023-35698 | MEDIUM | 5.3 | 0.6% | Jul 10, 2023 | Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the F... |
| CVE-2023-35697 | HIGH | 7.5 | 0.7% | Jul 10, 2023 | Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-fo... |
| CVE-2023-35696 | HIGH | 7.5 | 0.7% | Jul 10, 2023 | Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive info... |
| CVE-2023-34682 | — | — | — | Jul 10, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-34442 | LOW | 3.3 | 0.3% | Jul 10, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This... |
| CVE-2023-32254 | HIGH | 8.1 | 2.9% | Jul 10, 2023 | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within t... |
| CVE-2023-32250 | HIGH | 8.1 | 2.6% | Jul 10, 2023 | A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within t... |
| CVE-2023-30449 | HIGH | 7.5 | 1.1% | Jul 10, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic... |
| CVE-2023-30448 | HIGH | 7.5 | 1.1% | Jul 10, 2023 | IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now