2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0116 | HIGH | 7.5 | 0.5% | May 26, 2023 | The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerabi... |
| CVE-2023-33720 | MEDIUM | 6.5 | 0.6% | May 26, 2023 | mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty. |
| CVE-2023-33440 | HIGH | 7.2 | 14.5% | May 26, 2023 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_u... |
| CVE-2023-33439 | HIGH | 7.2 | 3.3% | May 26, 2023 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=. |
| CVE-2023-33394 | MEDIUM | 5.4 | 0.4% | May 26, 2023 | skycaiji v2.5.4 is vulnerable to Cross Site Scripting (XSS). Attackers can achieve backend XSS by deploying malicious JS... |
| CVE-2023-32964 | HIGH | 8.8 | 0.3% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Made with Fuel Better Notifications for WP plugin <= 1.9.2 versions. |
| CVE-2023-30145 | CRITICAL | 9.8 | 46.1% | May 26, 2023 | Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para... |
| CVE-2023-29098 | MEDIUM | 6.1 | 0.4% | May 26, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ArtistScope CopySafe Web Protection plugin <= 3.13 version... |
| CVE-2023-25467 | HIGH | 8.8 | 0.2% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Daniel Mores, A. Huizinga Resize at Upload Plus plugin <= 1.3 version... |
| CVE-2023-25058 | HIGH | 8.8 | 0.3% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1... |
| CVE-2023-25034 | HIGH | 8.8 | 0.3% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in BoLiQuan WP Clean Up plugin <= 1.2.3 versions. |
| CVE-2023-32323 | MEDIUM | 4.3 | 1.0% | May 26, 2023 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. A malicious user on a S... |
| CVE-2023-25470 | HIGH | 8.8 | 0.3% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Anton Skorobogatov Rus-To-Lat plugin <= 0.3 versions. |
| CVE-2023-25029 | HIGH | 8.8 | 0.3% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in utahta WP Social Bookmarking Light plugin <= 2.0.7 versions. |
| CVE-2023-25038 | HIGH | 8.8 | 0.3% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in 984.Ru For the visually impaired plugin <= 0.58 versions. |
| CVE-2023-24008 | HIGH | 8.8 | 0.3% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in yonifre Maspik – Spam Blacklist plugin <= 0.7.8 versions. |
| CVE-2023-22693 | HIGH | 8.8 | 0.3% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in conlabzgmbh WP Google Tag Manager plugin <= 1.1 versions. |
| CVE-2023-25976 | HIGH | 8.8 | 0.3% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin plugin <... |
| CVE-2023-25971 | HIGH | 8.8 | 0.3% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in FixBD Educare plugin <= 1.4.1 versions. |
| CVE-2023-25781 | MEDIUM | 4.8 | 0.4% | May 26, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sebastian Krysmanski Upload File Type Settings plugin ... |
| CVE-2023-24007 | HIGH | 8.8 | 0.3% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in TheOnlineHero - Tom Skroza Admin Block Country plugin <= 7.1.4 versio... |
| CVE-2023-23714 | HIGH | 8.8 | 0.3% | May 26, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash plugin <= 3.6.4.1 versions. |
| CVE-2023-28382 | HIGH | 8.1 | 0.9% | May 26, 2023 | Directory traversal vulnerability in ESS REC Agent Server Edition series allows an authenticated attacker to view or alt... |
| CVE-2023-32074 | CRITICAL | 9.8 | 0.9% | May 25, 2023 | user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. I... |
| CVE-2023-32067 | HIGH | 7.5 | 1.6% | May 25, 2023 | c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a quer... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now