2023 CVE Vulnerabilities
31,440 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27733 | HIGH | 7.2 | 0.8% | Apr 17, 2023 | DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php. |
| CVE-2023-1473 | MEDIUM | 6.1 | 0.5% | Apr 17, 2023 | The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before ... |
| CVE-2023-1427 | MEDIUM | 4.9 | 0.8% | Apr 17, 2023 | - The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploa... |
| CVE-2023-1413 | MEDIUM | 6.1 | 0.5% | Apr 17, 2023 | The WP VR WordPress plugin before 8.2.9 does not sanitise and escape some parameters before outputting them back in the ... |
| CVE-2023-1373 | MEDIUM | 6.1 | 0.5% | Apr 17, 2023 | The W4 Post List WordPress plugin before 2.4.6 does not escape some URLs before outputting them in attributes, leading t... |
| CVE-2023-1371 | MEDIUM | 6.5 | 0.7% | Apr 17, 2023 | The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before disp... |
| CVE-2023-1331 | MEDIUM | 6.5 | 0.3% | Apr 17, 2023 | The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attac... |
| CVE-2023-1325 | MEDIUM | 5.4 | 0.5% | Apr 17, 2023 | The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes... |
| CVE-2023-1282 | MEDIUM | 6.1 | 0.5% | Apr 17, 2023 | The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Mu... |
| CVE-2023-1274 | MEDIUM | 6.5 | 0.9% | Apr 17, 2023 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate so... |
| CVE-2023-0889 | MEDIUM | 6.5 | 0.3% | Apr 17, 2023 | Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and do... |
| CVE-2023-0765 | HIGH | 8.8 | 0.9% | Apr 17, 2023 | The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to... |
| CVE-2023-0764 | MEDIUM | 5.4 | 0.4% | Apr 17, 2023 | The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, le... |
| CVE-2023-0374 | MEDIUM | 5.4 | 0.4% | Apr 17, 2023 | The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting ... |
| CVE-2023-0367 | MEDIUM | 5.4 | 0.4% | Apr 17, 2023 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate an... |
| CVE-2023-0277 | HIGH | 7.2 | 0.9% | Apr 17, 2023 | The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it i... |
| CVE-2023-1723 | CRITICAL | 9.8 | 0.6% | Apr 17, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile A... |
| CVE-2023-2017 | HIGH | 8.8 | 2.1% | Apr 17, 2023 | Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopwar... |
| CVE-2023-30771 | CRITICAL | 9.8 | 1.4% | Apr 17, 2023 | Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbe... |
| CVE-2023-22946 | CRITICAL | 9.9 | 1.1% | Apr 17, 2023 | In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting ... |
| CVE-2023-1109 | HIGH | 8.8 | 0.8% | Apr 17, 2023 | In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, wri... |
| CVE-2023-30770 | CRITICAL | 9.8 | 0.6% | Apr 17, 2023 | A stack-based buffer overflow vulnerability was found in the ASUSTOR Data Master (ADM) due to the lack of data size vali... |
| CVE-2023-24831 | CRITICAL | 9.8 | 1.2% | Apr 17, 2023 | Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana... |
| CVE-2023-2109 | MEDIUM | 6.1 | 0.4% | Apr 17, 2023 | Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0. |
| CVE-2023-22687 | HIGH | 7.5 | 0.5% | Apr 16, 2023 | Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now