2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29780HIGH7.5Third Reality Smart Blind 1.00.54 contains a denial-of-service vulnerability, which allows a remote attacker to send mal...
CVE-2023-1624MEDIUM6.5The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be de...
CVE-2023-1623MEDIUM6.5The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug informati...
CVE-2023-1435MEDIUM6.1The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting the...
CVE-2023-1420MEDIUM6.1The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise an...
CVE-2023-1414MEDIUM4.3The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in part...
CVE-2023-1324MEDIUM6.1The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputtin...
CVE-2023-1129MEDIUM6.5The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making...
CVE-2023-1126MEDIUM5.4The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any au...
CVE-2023-1020CRITICAL9.8The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using i...
CVE-2023-0899MEDIUM6.1The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputt...
CVE-2023-0424MEDIUM5.4The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authentica...
CVE-2023-0420MEDIUM4.8The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising...
CVE-2023-0418MEDIUM5.4The Video Central for WordPress plugin through 1.3.0 does not validate and escape some of its shortcode attributes befor...
CVE-2023-0388HIGH8.8The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQ...
CVE-2023-0276MEDIUM5.4The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attribu...
CVE-2023-29566CRITICAL9.8huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (...
CVE-2023-27991HIGH8.8The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 th...
CVE-2023-27990MEDIUM4.8The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series fi...
CVE-2023-27849CRITICAL9.8rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process ...
CVE-2023-27848CRITICAL9.8broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process func...
CVE-2023-26865CRITICAL9.8SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privilege...
CVE-2023-26099HIGH7.1An issue was discovered in Telindus Apsal 3.14.2022.235 b. The consultation permission is insecure.
CVE-2023-26097MEDIUM5.5An issue was discovered in Telindus Apsal 3.14.2022.235 b. Unauthorized actions that could modify the application behavi...
CVE-2023-26059MEDIUM5.4An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now