2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27733HIGH7.2DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php.
CVE-2023-1473MEDIUM6.1The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before ...
CVE-2023-1427MEDIUM4.9- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploa...
CVE-2023-1413MEDIUM6.1The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the ...
CVE-2023-1373MEDIUM6.1The W4 Post List WordPress plugin before 2.4.6 does not escape some URLs before outputting them in attributes, leading t...
CVE-2023-1371MEDIUM6.5The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before disp...
CVE-2023-1331MEDIUM6.5The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attac...
CVE-2023-1325MEDIUM5.4The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes...
CVE-2023-1282MEDIUM6.1The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Mu...
CVE-2023-1274MEDIUM6.5The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate so...
CVE-2023-0889MEDIUM6.5Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and do...
CVE-2023-0765HIGH8.8The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to...
CVE-2023-0764MEDIUM5.4The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, le...
CVE-2023-0374MEDIUM5.4The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting ...
CVE-2023-0367MEDIUM5.4The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate an...
CVE-2023-0277HIGH7.2The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it i...
CVE-2023-1723CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile A...
CVE-2023-2017HIGH8.8Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopwar...
CVE-2023-30771CRITICAL9.8Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbe...
CVE-2023-22946CRITICAL9.9In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting ...
CVE-2023-1109HIGH8.8In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, wri...
CVE-2023-30770CRITICAL9.8A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size vali...
CVE-2023-24831CRITICAL9.8Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana...
CVE-2023-2109MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.
CVE-2023-22687HIGH7.5Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now