2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36684 | CRITICAL | 9.8 | 0.5% | Jun 19, 2024 | Missing Authorization vulnerability in Brainstorm Force Convert Pro.This issue affects Convert Pro: from n/a through 1.7... |
| CVE-2023-38386 | CRITICAL | 9.8 | 0.4% | Jun 19, 2024 | Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.2... |
| CVE-2023-35049 | CRITICAL | 9.8 | 0.5% | Jun 19, 2024 | Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Str... |
| CVE-2023-48760 | CRITICAL | 9.8 | 0.4% | Jun 19, 2024 | Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor... |
| CVE-2023-37058 | CRITICAL | 9.8 | 0.7% | Jun 17, 2024 | Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to e... |
| CVE-2023-37057 | CRITICAL | 9.8 | 0.9% | Jun 17, 2024 | An issue in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to execute arbitrary code via ... |
| CVE-2023-36504 | CRITICAL | 9.8 | 0.4% | Jun 14, 2024 | Missing Authorization vulnerability in BBS e-Theme BBS e-Popup.This issue affects BBS e-Popup: from n/a through 2.4.5. |
| CVE-2023-35040 | CRITICAL | 9.8 | 0.3% | Jun 14, 2024 | Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/... |
| CVE-2023-52233 | CRITICAL | 9.8 | 0.4% | Jun 11, 2024 | Missing Authorization vulnerability in Post SMTP Post SMTP Mailer/Email Log.This issue affects Post SMTP Mailer/Email Lo... |
| CVE-2023-7264 | CRITICAL | 9.8 | 0.6% | Jun 11, 2024 | The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in al... |
| CVE-2023-45188 | CRITICAL | 9.8 | 0.7% | Jun 9, 2024 | IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files... |
| CVE-2023-51494 | CRITICAL | 9.8 | 0.4% | Jun 9, 2024 | Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: f... |
| CVE-2023-47189 | CRITICAL | 9.8 | 0.5% | Jun 4, 2024 | Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrai... |
| CVE-2023-40332 | CRITICAL | 9.8 | 0.4% | Jun 4, 2024 | Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misu... |
| CVE-2023-24373 | CRITICAL | 9.8 | 0.4% | Jun 3, 2024 | External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking Syst... |
| CVE-2023-51219 | CRITICAL | 9.6 | 0.5% | Jun 3, 2024 | A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controll... |
| CVE-2023-43845 | CRITICAL | 9.8 | 0.5% | May 28, 2024 | Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to cha... |
| CVE-2023-51637 | CRITICAL | 9.8 | 1.0% | May 22, 2024 | Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2023-52832 | CRITICAL | 9.1 | 1.3% | May 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't return unset power in ieee802... |
| CVE-2023-52755 | CRITICAL | 9.8 | 26.9% | May 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab out of bounds write in smb_inherit_... |
| CVE-2023-52735 | CRITICAL | 9.1 | 1.2% | May 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Don't let sock_map_{close,destroy,unh... |
| CVE-2023-3943 | CRITICAL | 10 | 0.9% | May 21, 2024 | Stack-based Buffer Overflow vulnerability in ZkTeco-based OEM devices allows, in some cases, the execution of arbitrary ... |
| CVE-2023-3941 | CRITICAL | 10 | 0.9% | May 21, 2024 | Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to write any file on the system w... |
| CVE-2023-3939 | CRITICAL | 10 | 1.3% | May 21, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in ZkTeco-base... |
| CVE-2023-51483 | CRITICAL | 9.8 | 0.5% | May 17, 2024 | Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affe... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now