2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6373 | HIGH | 8.8 | 0.4% | Jan 16, 2024 | The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting th... |
| CVE-2023-5922 | HIGH | 7.5 | 0.7% | Jan 16, 2024 | The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via a... |
| CVE-2023-4797 | HIGH | 7.2 | 1.0% | Jan 16, 2024 | The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended... |
| CVE-2023-4703 | HIGH | 7.5 | 0.6% | Jan 16, 2024 | The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating us... |
| CVE-2023-4536 | HIGH | 8.8 | 0.8% | Jan 16, 2024 | The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing ... |
| CVE-2023-45237 | HIGH | 7.5 | 1.0% | Jan 16, 2024 | EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited... |
| CVE-2023-45236 | HIGH | 7.5 | 1.0% | Jan 16, 2024 | EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited... |
| CVE-2023-45235 | HIGH | 8.8 | 1.2% | Jan 16, 2024 | EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a... |
| CVE-2023-45234 | HIGH | 8.8 | 1.2% | Jan 16, 2024 | EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv... |
| CVE-2023-45233 | HIGH | 7.5 | 2.1% | Jan 16, 2024 | EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Opt... |
| CVE-2023-45232 | HIGH | 7.5 | 2.1% | Jan 16, 2024 | EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination ... |
| CVE-2023-45230 | HIGH | 8.8 | 1.2% | Jan 16, 2024 | EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. T... |
| CVE-2023-2655 | HIGH | 7.2 | 0.9% | Jan 16, 2024 | The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using i... |
| CVE-2023-1405 | HIGH | 7.5 | 0.7% | Jan 16, 2024 | The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform P... |
| CVE-2023-52105 | HIGH | 7.5 | 0.4% | Jan 16, 2024 | The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect ava... |
| CVE-2023-52104 | HIGH | 7.5 | 0.3% | Jan 16, 2024 | Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affe... |
| CVE-2023-52102 | HIGH | 7.5 | 0.3% | Jan 16, 2024 | Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affe... |
| CVE-2023-52100 | HIGH | 7.5 | 0.4% | Jan 16, 2024 | The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affec... |
| CVE-2023-52099 | HIGH | 7.5 | 0.3% | Jan 16, 2024 | Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulne... |
| CVE-2023-34063 | HIGH | 8.3 | 0.9% | Jan 16, 2024 | Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vu... |
| CVE-2023-52116 | HIGH | 7.5 | 0.4% | Jan 16, 2024 | Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerabilit... |
| CVE-2023-52115 | HIGH | 7.5 | 0.4% | Jan 16, 2024 | The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the... |
| CVE-2023-52114 | HIGH | 7.5 | 0.3% | Jan 16, 2024 | Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect ... |
| CVE-2023-52108 | HIGH | 7.5 | 0.4% | Jan 16, 2024 | Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this v... |
| CVE-2023-52107 | HIGH | 7.5 | 0.3% | Jan 16, 2024 | Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerabilit... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now