2023 CVE Vulnerabilities

31,416 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-30869CRITICAL9.8Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue a...
CVE-2023-32007HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option s...
CVE-2023-31207MEDIUM5.5Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause...
CVE-2023-2000MEDIUM5.4Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
CVE-2023-1196HIGH8.8The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user ...
CVE-2023-1911MEDIUM4.3The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are alrea...
CVE-2023-1861MEDIUM5.4The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back...
CVE-2023-1809HIGH7.5The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowin...
CVE-2023-1805MEDIUM6.1The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the page parameter ...
CVE-2023-1804MEDIUM6.1The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter ...
CVE-2023-1730CRITICAL9.8The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL stateme...
CVE-2023-1669HIGH7.2The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-p...
CVE-2023-1614MEDIUM4.8The WP Custom Author URL WordPress plugin before 1.0.5 does not sanitise and escape some of its settings, which could al...
CVE-2023-1554MEDIUM4.8The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which coul...
CVE-2023-1546MEDIUM6.1The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leadi...
CVE-2023-1525MEDIUM4.8The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-1125MEDIUM6.5The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user maki...
CVE-2023-1090MEDIUM4.8The SMTP Mailing Queue WordPress plugin before 2.0.1 does not sanitise and escape some of its settings, which could allo...
CVE-2023-1021MEDIUM4.8The amr ical events lists WordPress plugin through 6.6 does not sanitise and escape some of its settings, which could al...
CVE-2023-0924HIGH7.2The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowin...
CVE-2023-0891MEDIUM5.4The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputt...
CVE-2023-21666HIGH7.8Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
CVE-2023-21665HIGH7.8Memory corruption in Graphics while importing a file.
CVE-2023-21642HIGH7.8Memory corruption in HAB Memory management due to broad system privileges via physical address.
CVE-2023-2247MEDIUM5.3In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now