2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-52048 | MEDIUM | 4.7 | 0.3% | Feb 28, 2024 | RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/. |
| CVE-2023-51692 | MEDIUM | 4.3 | 0.3% | Feb 28, 2024 | Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for W... |
| CVE-2023-51533 | MEDIUM | 6.1 | 0.2% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwi... |
| CVE-2023-51681 | MEDIUM | 6.5 | 0.3% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issu... |
| CVE-2023-6917 | MEDIUM | 6.7 | 0.2% | Feb 28, 2024 | A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels ... |
| CVE-2023-6922 | MEDIUM | 6.5 | 0.5% | Feb 28, 2024 | The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu... |
| CVE-2023-50303 | MEDIUM | 6.1 | 0.4% | Feb 28, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2023-50380 | MEDIUM | 6.5 | 0.9% | Feb 27, 2024 | XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, whi... |
| CVE-2023-48682 | MEDIUM | 5.4 | 0.3% | Feb 27, 2024 | Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect... |
| CVE-2023-48681 | MEDIUM | 6.1 | 0.3% | Feb 27, 2024 | Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acroni... |
| CVE-2023-48680 | MEDIUM | 5.5 | 0.2% | Feb 27, 2024 | Sensitive information disclosure due to excessive collection of system information. The following products are affected:... |
| CVE-2023-48679 | MEDIUM | 5.4 | 0.3% | Feb 27, 2024 | Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products ... |
| CVE-2023-48678 | MEDIUM | 5.5 | 0.2% | Feb 27, 2024 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber ... |
| CVE-2023-7203 | MEDIUM | 6.1 | 0.2% | Feb 27, 2024 | The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow us... |
| CVE-2023-7202 | MEDIUM | 6.1 | 0.2% | Feb 27, 2024 | The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX ... |
| CVE-2023-7198 | MEDIUM | 4.3 | 0.4% | Feb 27, 2024 | The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_... |
| CVE-2023-7167 | MEDIUM | 6.1 | 0.4% | Feb 27, 2024 | The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2023-7115 | MEDIUM | 4.8 | 0.4% | Feb 27, 2024 | The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could... |
| CVE-2023-7033 | MEDIUM | 5.3 | 0.9% | Feb 27, 2024 | Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU ... |
| CVE-2023-52473 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix NULL pointer dereference in zone... |
| CVE-2023-52472 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: crypto: rsa - add a check for allocation failure S... |
| CVE-2023-52471 | MEDIUM | 5.5 | 0.2% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: ice: Fix some null pointer dereference issues in ic... |
| CVE-2023-52470 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/radeon: check the alloc_workqueue return value ... |
| CVE-2023-52467 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: mfd: syscon: Fix null pointer dereference in of_sys... |
| CVE-2023-52465 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: power: supply: Fix null pointer dereference in smb2... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now