2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2276 | CRITICAL | 9.8 | 1.1% | May 20, 2023 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure... |
| CVE-2023-2736 | HIGH | 8 | 0.4% | May 20, 2023 | The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.... |
| CVE-2023-2735 | MEDIUM | 5.4 | 0.5% | May 20, 2023 | The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gh_form' shortcode in versions... |
| CVE-2023-2717 | MEDIUM | 4.3 | 0.3% | May 20, 2023 | The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.... |
| CVE-2023-2716 | MEDIUM | 5.4 | 0.5% | May 20, 2023 | The Groundhogg plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missi... |
| CVE-2023-2715 | MEDIUM | 4.3 | 0.6% | May 20, 2023 | The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2023-2714 | MEDIUM | 4.3 | 0.5% | May 20, 2023 | The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2023-28623 | LOW | 3.7 | 0.5% | May 19, 2023 | Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBa... |
| CVE-2023-32677 | LOW | 3.1 | 0.6% | May 19, 2023 | Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zu... |
| CVE-2023-32679 | HIGH | 7.2 | 1.8% | May 19, 2023 | Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension ... |
| CVE-2023-32675 | MEDIUM | 5.3 | 0.6% | May 19, 2023 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In contracts with more than one regular no... |
| CVE-2023-2815 | CRITICAL | 9.8 | 0.7% | May 19, 2023 | A vulnerability classified as critical was found in SourceCodester Online Jewelry Store 1.0. Affected by this vulnerabil... |
| CVE-2023-2814 | MEDIUM | 6.1 | 0.6% | May 19, 2023 | A vulnerability classified as problematic has been found in SourceCodester Class Scheduling System 1.0. Affected is an u... |
| CVE-2023-1996 | MEDIUM | 6.1 | 0.4% | May 19, 2023 | A reflected Cross-site Scripting (XSS) vulnerability in Release 3DEXPERIENCE R2018x through Release 3DEXPERIENCE R2023x ... |
| CVE-2023-28950 | MEDIUM | 5.5 | 0.2% | May 19, 2023 | IBM MQ 8.0, 9.0, 9.1, 9.2, and 9.3 could disclose sensitive user information from a trace file if that functionality has... |
| CVE-2023-28529 | MEDIUM | 5.4 | 0.4% | May 19, 2023 | IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to ... |
| CVE-2023-22878 | MEDIUM | 5.5 | 0.1% | May 19, 2023 | IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. I... |
| CVE-2023-30775 | MEDIUM | 5.5 | 0.3% | May 19, 2023 | A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSampl... |
| CVE-2023-30774 | MEDIUM | 5.5 | 0.5% | May 19, 2023 | A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES... |
| CVE-2023-28514 | MEDIUM | 5.5 | 0.2% | May 19, 2023 | IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical e... |
| CVE-2023-20881 | HIGH | 8.1 | 0.4% | May 19, 2023 | Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override othe... |
| CVE-2023-31757 | MEDIUM | 5.4 | 0.4% | May 19, 2023 | DedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian' |
| CVE-2023-31707 | CRITICAL | 9.8 | 0.8% | May 19, 2023 | SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php. |
| CVE-2023-30199 | HIGH | 7.5 | 0.7% | May 19, 2023 | Prestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/downl... |
| CVE-2023-31862 | MEDIUM | 5.4 | 0.3% | May 19, 2023 | jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is on... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now