2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32007HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option s...
CVE-2023-31207MEDIUM5.5Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause...
CVE-2023-2000MEDIUM5.4Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
CVE-2023-1196HIGH8.8The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user ...
CVE-2023-1911MEDIUM4.3The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are alrea...
CVE-2023-1861MEDIUM5.4The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back...
CVE-2023-1809HIGH7.5The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowin...
CVE-2023-1805MEDIUM6.1The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the page parameter ...
CVE-2023-1804MEDIUM6.1The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the edit parameter ...
CVE-2023-1730CRITICAL9.8The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL stateme...
CVE-2023-1669HIGH7.2The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-p...
CVE-2023-1614MEDIUM4.8The WP Custom Author URL WordPress plugin before 1.0.5 does not sanitise and escape some of its settings, which could al...
CVE-2023-1554MEDIUM4.8The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which coul...
CVE-2023-1546MEDIUM6.1The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leadi...
CVE-2023-1525MEDIUM4.8The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-1125MEDIUM6.5The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user maki...
CVE-2023-1090MEDIUM4.8The SMTP Mailing Queue WordPress plugin before 2.0.1 does not sanitise and escape some of its settings, which could allo...
CVE-2023-1021MEDIUM4.8The amr ical events lists WordPress plugin through 6.6 does not sanitise and escape some of its settings, which could al...
CVE-2023-0924HIGH7.2The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowin...
CVE-2023-0891MEDIUM5.4The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputt...
CVE-2023-21666HIGH7.8Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
CVE-2023-21665HIGH7.8Memory corruption in Graphics while importing a file.
CVE-2023-21642HIGH7.8Memory corruption in HAB Memory management due to broad system privileges via physical address.
CVE-2023-2247MEDIUM5.3In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function
CVE-2023-30639MEDIUM5.4Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability. A remote authenticated maliciou...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now