2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6725 | MEDIUM | 5.5 | 0.2% | Mar 15, 2024 | An access-control flaw was found in the OpenStack Designate component where private configuration information including ... |
| CVE-2023-43490 | MEDIUM | 5.3 | 0.2% | Mar 14, 2024 | Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a... |
| CVE-2023-39368 | MEDIUM | 6.5 | 0.8% | Mar 14, 2024 | Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to pot... |
| CVE-2023-38575 | MEDIUM | 5.5 | 0.3% | Mar 14, 2024 | Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized... |
| CVE-2023-35191 | MEDIUM | 6.8 | 0.5% | Mar 14, 2024 | Uncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially ena... |
| CVE-2023-32633 | MEDIUM | 6.7 | 0.2% | Mar 14, 2024 | Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated u... |
| CVE-2023-28746 | MEDIUM | 6.5 | 0.5% | Mar 14, 2024 | Information exposure through microarchitectural state after transient execution from some register files for some Intel(... |
| CVE-2023-28389 | MEDIUM | 6.7 | 0.1% | Mar 14, 2024 | Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authentica... |
| CVE-2023-22655 | MEDIUM | 6.1 | 0.2% | Mar 14, 2024 | Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel... |
| CVE-2023-38536 | MEDIUM | 6.1 | 0.4% | Mar 13, 2024 | HTML injection in OpenText™ Exceed Turbo X affecting version 12.5.1. The vulnerability could result in Cross site script... |
| CVE-2023-50726 | MEDIUM | 6.4 | 0.5% | Mar 13, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows... |
| CVE-2023-36238 | MEDIUM | 6.5 | 0.5% | Mar 13, 2024 | Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the in... |
| CVE-2023-7015 | MEDIUM | 6.1 | 0.5% | Mar 13, 2024 | The File Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tb' parameter in all ... |
| CVE-2023-6969 | MEDIUM | 4.3 | 0.5% | Mar 13, 2024 | The User Shortcodes Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a... |
| CVE-2023-6957 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2023-6954 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)... |
| CVE-2023-6880 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages pl... |
| CVE-2023-6809 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Custom fields shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf shortc... |
| CVE-2023-6785 | MEDIUM | 5.3 | 0.5% | Mar 13, 2024 | The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in a... |
| CVE-2023-52608 | MEDIUM | 4.7 | 0.2% | Mar 13, 2024 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Check mailbox/SMT channel for c... |
| CVE-2023-43043 | MEDIUM | 5.5 | 0.2% | Mar 13, 2024 | IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user.... |
| CVE-2023-38723 | MEDIUM | 6.4 | 0.3% | Mar 13, 2024 | IBM Maximo Application Suite 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to em... |
| CVE-2023-28517 | MEDIUM | 5.4 | 0.3% | Mar 13, 2024 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to cross-site scripting. This vulnerabilit... |
| CVE-2023-4839 | MEDIUM | 4.8 | 0.3% | Mar 13, 2024 | The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and incl... |
| CVE-2023-43279 | MEDIUM | 6.5 | 0.7% | Mar 12, 2024 | Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now