2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34342 | CRITICAL | 9.1 | 0.5% | Jun 12, 2023 | AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under ce... |
| CVE-2023-34336 | HIGH | 8.8 | 0.7% | Jun 12, 2023 | AMI BMC contains a vulnerability in the IPMI handler, where an attacker with the required privileges can cause a buffer ... |
| CVE-2023-34335 | CRITICAL | 9.1 | 0.4% | Jun 12, 2023 | AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI fl... |
| CVE-2023-34334 | HIGH | 8.8 | 0.8% | Jun 12, 2023 | AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrar... |
| CVE-2023-2718 | MEDIUM | 5.4 | 0.5% | Jun 12, 2023 | The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTM... |
| CVE-2023-2568 | MEDIUM | 6.1 | 0.5% | Jun 12, 2023 | The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attr... |
| CVE-2023-2398 | MEDIUM | 6.1 | 0.5% | Jun 12, 2023 | The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute,... |
| CVE-2023-2362 | MEDIUM | 6.1 | 0.5% | Jun 12, 2023 | The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plug... |
| CVE-2023-1323 | MEDIUM | 4.8 | 0.4% | Jun 12, 2023 | The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, whi... |
| CVE-2023-0431 | MEDIUM | 5.4 | 0.4% | Jun 12, 2023 | The File Away WordPress plugin through 3.9.9.0.1 does not validate and escape one of its shortcode attributes, which cou... |
| CVE-2023-34345 | MEDIUM | 6.5 | 0.7% | Jun 12, 2023 | AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can access arbitrar... |
| CVE-2023-34344 | MEDIUM | 5.3 | 0.4% | Jun 12, 2023 | AMI BMC contains a vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a ... |
| CVE-2023-34341 | HIGH | 8.8 | 0.8% | Jun 12, 2023 | AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can read and write ... |
| CVE-2023-34246 | MEDIUM | 6.5 | 0.7% | Jun 12, 2023 | Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes ... |
| CVE-2023-34105 | HIGH | 7.5 | 8.8% | Jun 12, 2023 | SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5... |
| CVE-2023-30198 | HIGH | 7.5 | 5.5% | Jun 12, 2023 | Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download... |
| CVE-2023-35054 | MEDIUM | 5.4 | 1.0% | Jun 12, 2023 | In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible |
| CVE-2023-35053 | HIGH | 7.5 | 0.6% | Jun 12, 2023 | In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms |
| CVE-2023-34468 | HIGH | 8.8 | 63.4% | Jun 12, 2023 | The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authe... |
| CVE-2023-34212 | MEDIUM | 6.5 | 2.4% | Jun 12, 2023 | The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache ... |
| CVE-2023-34026 | MEDIUM | 6.1 | 0.4% | Jun 12, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in BrokenCrust This Day In History plugin <= 3.10.1 versions. |
| CVE-2023-29385 | MEDIUM | 6.1 | 0.4% | Jun 12, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions. |
| CVE-2023-28933 | MEDIUM | 4.8 | 0.4% | Jun 12, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in StPeteDesign Call Now Accessibility Button plugin <= 1... |
| CVE-2023-3208 | HIGH | 8.8 | 0.7% | Jun 12, 2023 | A vulnerability, which was classified as critical, has been found in RoadFlow Visual Process Engine .NET Core Mvc 2.13.3... |
| CVE-2023-3206 | HIGH | 7.5 | 18.7% | Jun 12, 2023 | A vulnerability classified as problematic was found in Chengdu VEC40G 3.0. Affected by this vulnerability is an unknown ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now