2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3473 | CRITICAL | 9.8 | 0.7% | Jun 30, 2023 | A vulnerability, which was classified as critical, was found in Campcodes Retro Cellphone Online Store 1.0. Affected is ... |
| CVE-2023-28387 | MEDIUM | 5.5 | 0.2% | Jun 30, 2023 | "NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard... |
| CVE-2023-32622 | HIGH | 7.2 | 0.6% | Jun 30, 2023 | Improper neutralization of special elements in WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an... |
| CVE-2023-32621 | HIGH | 7.2 | 0.6% | Jun 30, 2023 | WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to upload arbitrary f... |
| CVE-2023-32620 | MEDIUM | 6.5 | 0.3% | Jun 30, 2023 | Improper authentication vulnerability in WL-WN531AX2 firmware versions prior to 2023526 allows a network-adjacent attack... |
| CVE-2023-32613 | HIGH | 8.1 | 0.3% | Jun 30, 2023 | Exposure of resource to wrong sphere issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow a n... |
| CVE-2023-32612 | HIGH | 7.2 | 0.6% | Jun 30, 2023 | Client-side enforcement of server-side security issue exists in WL-WN531AX2 firmware versions prior to 2023526, which ma... |
| CVE-2023-2846 | CRITICAL | 9.1 | 0.9% | Jun 30, 2023 | Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series main modules... |
| CVE-2023-26135 | CRITICAL | 9.8 | 0.7% | Jun 30, 2023 | All versions of the package flatnest are vulnerable to Prototype Pollution via the nest() function in the flatnest/nest.... |
| CVE-2023-36539 | HIGH | 7.5 | 0.4% | Jun 30, 2023 | Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. |
| CVE-2023-32608 | MEDIUM | 6.5 | 1.2% | Jun 30, 2023 | Directory traversal vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions... |
| CVE-2023-32607 | MEDIUM | 5.4 | 0.5% | Jun 30, 2023 | Stored cross-site scripting vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier... |
| CVE-2023-3249 | CRITICAL | 9.8 | 0.9% | Jun 30, 2023 | The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in version... |
| CVE-2023-3063 | HIGH | 8.8 | 0.6% | Jun 30, 2023 | The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up... |
| CVE-2023-36347 | HIGH | 7.5 | 32.4% | Jun 30, 2023 | A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to down... |
| CVE-2023-33336 | MEDIUM | 4.8 | 0.5% | Jun 30, 2023 | Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbit... |
| CVE-2023-2834 | CRITICAL | 9.8 | 1.9% | Jun 30, 2023 | The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is ... |
| CVE-2023-3469 | MEDIUM | 4.8 | 0.6% | Jun 30, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.2. |
| CVE-2023-36146 | MEDIUM | 5.4 | 0.5% | Jun 30, 2023 | A Stored Cross-Site Scripting (XSS) vulnerability was found in Multilaser RE 170 using firmware 2.2.6733. |
| CVE-2023-36143 | HIGH | 8.8 | 3.0% | Jun 30, 2023 | Maxprint Maxlink 1200G v3.4.11E has an OS command injection vulnerability in the "Diagnostic tool" functionality of the ... |
| CVE-2023-3465 | MEDIUM | 6.1 | 0.4% | Jun 29, 2023 | A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected b... |
| CVE-2023-3464 | MEDIUM | 6.1 | 0.4% | Jun 29, 2023 | A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected... |
| CVE-2023-36607 | MEDIUM | 5.3 | 0.4% | Jun 29, 2023 | The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could... |
| CVE-2023-36470 | HIGH | 8.8 | 1.7% | Jun 29, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creat... |
| CVE-2023-36469 | HIGH | 8.8 | 82.7% | Jun 29, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who ca... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now