2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34342CRITICAL9.1AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under ce...
CVE-2023-34336HIGH8.8AMI BMC contains a vulnerability in the IPMI handler, where an attacker with the required privileges can cause a buffer ...
CVE-2023-34335CRITICAL9.1AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI fl...
CVE-2023-34334HIGH8.8AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrar...
CVE-2023-2718MEDIUM5.4The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTM...
CVE-2023-2568MEDIUM6.1The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attr...
CVE-2023-2398MEDIUM6.1The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute,...
CVE-2023-2362MEDIUM6.1The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plug...
CVE-2023-1323MEDIUM4.8The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, whi...
CVE-2023-0431MEDIUM5.4The File Away WordPress plugin through 3.9.9.0.1 does not validate and escape one of its shortcode attributes, which cou...
CVE-2023-34345MEDIUM6.5AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can access arbitrar...
CVE-2023-34344MEDIUM5.3AMI BMC contains a vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a ...
CVE-2023-34341HIGH8.8AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can read and write ...
CVE-2023-34246MEDIUM6.5Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes ...
CVE-2023-34105HIGH7.5SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5...
CVE-2023-30198HIGH7.5Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download...
CVE-2023-35054MEDIUM5.4In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible
CVE-2023-35053HIGH7.5In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
CVE-2023-34468HIGH8.8The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authe...
CVE-2023-34212MEDIUM6.5The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache ...
CVE-2023-34026MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in BrokenCrust This Day In History plugin <= 3.10.1 versions.
CVE-2023-29385MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions.
CVE-2023-28933MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in StPeteDesign Call Now Accessibility Button plugin <= 1...
CVE-2023-3208HIGH8.8A vulnerability, which was classified as critical, has been found in RoadFlow Visual Process Engine .NET Core Mvc 2.13.3...
CVE-2023-3206HIGH7.5A vulnerability classified as problematic was found in Chengdu VEC40G 3.0. Affected by this vulnerability is an unknown ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now