2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2984 | HIGH | 8.8 | 0.9% | May 30, 2023 | Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. |
| CVE-2023-2983 | HIGH | 8.8 | 0.9% | May 30, 2023 | Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23. |
| CVE-2023-2981 | MEDIUM | 5.4 | 0.7% | May 30, 2023 | A vulnerability, which was classified as problematic, has been found in Abstrium Pydio Cells 4.2.0. This issue affects s... |
| CVE-2023-2980 | HIGH | 8.8 | 1.1% | May 30, 2023 | A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. This vulnerability affects unknown code ... |
| CVE-2023-2979 | HIGH | 8.8 | 0.8% | May 30, 2023 | A vulnerability classified as critical has been found in Abstrium Pydio Cells 4.2.0. This affects an unknown part of the... |
| CVE-2023-2978 | MEDIUM | 4.3 | 0.7% | May 30, 2023 | A vulnerability was found in Abstrium Pydio Cells 4.2.0. It has been rated as problematic. Affected by this issue is som... |
| CVE-2023-2650 | MEDIUM | 6.5 | 76.5% | May 30, 2023 | Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Imp... |
| CVE-2023-30196 | HIGH | 7.5 | 0.5% | May 30, 2023 | Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.... |
| CVE-2023-33234 | HIGH | 7.2 | 1.5% | May 30, 2023 | Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar ima... |
| CVE-2023-2973 | MEDIUM | 6.1 | 0.6% | May 30, 2023 | A vulnerability, which was classified as problematic, has been found in SourceCodester Students Online Internship Timesh... |
| CVE-2023-2972 | CRITICAL | 9.8 | 1.0% | May 30, 2023 | Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3. |
| CVE-2023-30601 | HIGH | 7.8 | 0.3% | May 30, 2023 | Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user runn... |
| CVE-2023-2518 | MEDIUM | 6.1 | 1.1% | May 30, 2023 | The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it... |
| CVE-2023-2470 | MEDIUM | 4.8 | 0.5% | May 30, 2023 | The Add to Feedly WordPress plugin through 1.2.11 does not sanitize and escape its settings, allowing high-privilege use... |
| CVE-2023-2296 | MEDIUM | 6.1 | 0.5% | May 30, 2023 | The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading t... |
| CVE-2023-2288 | HIGH | 8.8 | 18.0% | May 30, 2023 | The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operati... |
| CVE-2023-2287 | MEDIUM | 4.3 | 0.6% | May 30, 2023 | The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo imp... |
| CVE-2023-2256 | MEDIUM | 6.1 | 1.0% | May 30, 2023 | The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL paramet... |
| CVE-2023-2223 | MEDIUM | 4.8 | 0.6% | May 30, 2023 | The Login rebuilder WordPress plugin before 2.8.1 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2023-2117 | LOW | 2.7 | 0.7% | May 30, 2023 | The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_su... |
| CVE-2023-2113 | MEDIUM | 4.8 | 0.5% | May 30, 2023 | The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export,... |
| CVE-2023-2111 | MEDIUM | 4.9 | 0.8% | May 30, 2023 | The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL quer... |
| CVE-2023-2023 | MEDIUM | 6.1 | 1.7% | May 30, 2023 | The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading... |
| CVE-2023-1938 | HIGH | 8.8 | 8.5% | May 30, 2023 | The WP Fastest Cache WordPress plugin before 1.1.5 does not have CSRF check in an AJAX action, and does not validate use... |
| CVE-2023-1524 | MEDIUM | 6.5 | 0.7% | May 30, 2023 | The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now