2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-30447HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic...
CVE-2023-30446HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic...
CVE-2023-30445HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic...
CVE-2023-30442HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 federated server is vulnerable to a deni...
CVE-2023-30431HIGH7.8IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 db2set is vulnerable to a buffer ...
CVE-2023-2967MEDIUM4.8The TinyMCE Custom Styles WordPress plugin before 1.1.4 does not sanitise and escape some of its settings, which could a...
CVE-2023-2964MEDIUM5.4The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's conten...
CVE-2023-2853MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softmed SelfPatron...
CVE-2023-2852CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Softmed SelfPatron...
CVE-2023-2796MEDIUM5.3The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action...
CVE-2023-2709MEDIUM4.8The AN_GradeBook WordPress plugin through 5.0.1 does not sanitise and escape some of its settings, which could allow hig...
CVE-2023-2635MEDIUM4.8The Call Now Accessibility Button WordPress plugin before 1.1 does not sanitise and escape some of its settings, which c...
CVE-2023-2578MEDIUM4.8The Buy Me a Coffee WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow hig...
CVE-2023-2529MEDIUM5.4The Enable SVG Uploads WordPress plugin through 2.1.5 does not sanitise uploaded SVG files, which could allow users with...
CVE-2023-2495MEDIUM4.3The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyr...
CVE-2023-2493HIGH7.2The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters befor...
CVE-2023-2234HIGH8.8Union variant confusion allows any malicious BT controller to execute arbitrary code on the Zephyr host.
CVE-2023-2046CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yontem Informatics...
CVE-2023-2029MEDIUM4.8The PrePost SEO WordPress plugin through 3.0 does not properly sanitize some of its settings, which could allow high-pri...
CVE-2023-2028MEDIUM4.8The Call Now Accessibility Button WordPress plugin before 1.1 does not properly sanitize some of its settings, which cou...
CVE-2023-2026MEDIUM4.8The Image Protector WordPress plugin through 1.1 does not properly sanitize some of its settings, which could allow high...
CVE-2023-29256MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information d...
CVE-2023-29095HIGH7.2Auth. (admin+) SQL Injection (SQLi) vulnerability in David F. Carr RSVPMaker plugin < 10.5.5 versions.
CVE-2023-28995HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Keith Solomon Configurable Tag Cloud (CTC) plugin <= 5.2 versions.
CVE-2023-28989HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in weDevs Happy Addons for Elementor plugin <= 3.8.2 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now