2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0766 | HIGH | 8.8 | 0.4% | May 30, 2023 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF checks in some places, which could allow attackers ... |
| CVE-2023-0733 | MEDIUM | 6.1 | 0.5% | May 30, 2023 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow u... |
| CVE-2023-0443 | MEDIUM | 5.3 | 0.6% | May 30, 2023 | The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker ... |
| CVE-2023-0329 | HIGH | 7.2 | 19.7% | May 30, 2023 | The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL param... |
| CVE-2023-33955 | MEDIUM | 5.3 | 0.6% | May 30, 2023 | Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the orig... |
| CVE-2023-33191 | HIGH | 8.8 | 0.5% | May 30, 2023 | Kyverno is a policy engine designed for Kubernetes. Kyverno seccomp control can be circumvented. Users of the podSecurit... |
| CVE-2023-33193 | CRITICAL | 9.1 | 1.7% | May 30, 2023 | Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any for... |
| CVE-2023-33189 | CRITICAL | 9.8 | 0.9% | May 30, 2023 | Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisio... |
| CVE-2023-33186 | MEDIUM | 6.1 | 0.6% | May 30, 2023 | Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and ch... |
| CVE-2023-33183 | MEDIUM | 4.3 | 0.4% | May 30, 2023 | Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the websi... |
| CVE-2023-2970 | MEDIUM | 6.5 | 0.9% | May 30, 2023 | A vulnerability classified as problematic was found in MindSpore 2.0.0-alpha/2.0.0-rc1. This vulnerability affects the f... |
| CVE-2023-33245 | HIGH | 8.8 | 0.9% | May 30, 2023 | Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution... |
| CVE-2023-33198 | HIGH | 7.5 | 0.6% | May 30, 2023 | tgstation-server is a production scale tool for BYOND server management. The DreamMaker API (DMAPI) chat channel cache c... |
| CVE-2023-33182 | MEDIUM | 4.3 | 0.8% | May 30, 2023 | Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsani... |
| CVE-2023-33175 | HIGH | 7.5 | 0.7% | May 30, 2023 | ToUI is a Python package for creating user interfaces (websites and desktop apps) from HTML. ToUI is using Flask-Caching... |
| CVE-2023-32685 | MEDIUM | 5.4 | 0.5% | May 30, 2023 | Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements und... |
| CVE-2023-26130 | HIGH | 8.8 | 1.1% | May 30, 2023 | Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is ... |
| CVE-2023-34205 | CRITICAL | 9.1 | 0.4% | May 30, 2023 | In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canon... |
| CVE-2023-34204 | MEDIUM | 6.5 | 0.6% | May 30, 2023 | imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these ar... |
| CVE-2023-32698 | HIGH | 7.1 | 0.4% | May 30, 2023 | nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packag... |
| CVE-2023-32692 | CRITICAL | 9.8 | 1.1% | May 30, 2023 | CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you us... |
| CVE-2023-32691 | MEDIUM | 5.9 | 0.6% | May 30, 2023 | gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys sh... |
| CVE-2023-27988 | HIGH | 7.2 | 1.4% | May 30, 2023 | The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 ... |
| CVE-2023-32687 | MEDIUM | 6.5 | 0.6% | May 29, 2023 | tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instanc... |
| CVE-2023-32072 | MEDIUM | 4.8 | 0.5% | May 29, 2023 | Tuleap is an open source tool for end to end traceability of application and system developments. Tuleap Community Editi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now