2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29780 | HIGH | 7.5 | 1.1% | Apr 24, 2023 | Third Reality Smart Blind 1.00.54 contains a denial-of-service vulnerability, which allows a remote attacker to send mal... |
| CVE-2023-1624 | MEDIUM | 6.5 | 0.3% | Apr 24, 2023 | The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be de... |
| CVE-2023-1623 | MEDIUM | 6.5 | 0.4% | Apr 24, 2023 | The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug informati... |
| CVE-2023-1435 | MEDIUM | 6.1 | 0.5% | Apr 24, 2023 | The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting the... |
| CVE-2023-1420 | MEDIUM | 6.1 | 0.5% | Apr 24, 2023 | The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise an... |
| CVE-2023-1414 | MEDIUM | 4.3 | 0.2% | Apr 24, 2023 | The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in part... |
| CVE-2023-1324 | MEDIUM | 6.1 | 0.6% | Apr 24, 2023 | The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputtin... |
| CVE-2023-1129 | MEDIUM | 6.5 | 0.6% | Apr 24, 2023 | The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making... |
| CVE-2023-1126 | MEDIUM | 5.4 | 0.4% | Apr 24, 2023 | The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any au... |
| CVE-2023-1020 | CRITICAL | 9.8 | 5.0% | Apr 24, 2023 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using i... |
| CVE-2023-0899 | MEDIUM | 6.1 | 0.5% | Apr 24, 2023 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputt... |
| CVE-2023-0424 | MEDIUM | 5.4 | 0.4% | Apr 24, 2023 | The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authentica... |
| CVE-2023-0420 | MEDIUM | 4.8 | 0.2% | Apr 24, 2023 | The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising... |
| CVE-2023-0418 | MEDIUM | 5.4 | 0.4% | Apr 24, 2023 | The Video Central for WordPress plugin through 1.3.0 does not validate and escape some of its shortcode attributes befor... |
| CVE-2023-0388 | HIGH | 8.8 | 0.9% | Apr 24, 2023 | The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQ... |
| CVE-2023-0276 | MEDIUM | 5.4 | 0.5% | Apr 24, 2023 | The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attribu... |
| CVE-2023-29566 | CRITICAL | 9.8 | 2.2% | Apr 24, 2023 | huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (... |
| CVE-2023-27991 | HIGH | 8.8 | 1.5% | Apr 24, 2023 | The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 th... |
| CVE-2023-27990 | MEDIUM | 4.8 | 0.3% | Apr 24, 2023 | The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series fi... |
| CVE-2023-27849 | CRITICAL | 9.8 | 1.8% | Apr 24, 2023 | rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process ... |
| CVE-2023-27848 | CRITICAL | 9.8 | 1.9% | Apr 24, 2023 | broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process func... |
| CVE-2023-26865 | CRITICAL | 9.8 | 1.2% | Apr 24, 2023 | SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privilege... |
| CVE-2023-26099 | HIGH | 7.1 | 0.2% | Apr 24, 2023 | An issue was discovered in Telindus Apsal 3.14.2022.235 b. The consultation permission is insecure. |
| CVE-2023-26097 | MEDIUM | 5.5 | 0.2% | Apr 24, 2023 | An issue was discovered in Telindus Apsal 3.14.2022.235 b. Unauthorized actions that could modify the application behavi... |
| CVE-2023-26059 | MEDIUM | 5.4 | 0.4% | Apr 24, 2023 | An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now