2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1122MEDIUM4.8The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its Giveaways options, which co...
CVE-2023-1121MEDIUM4.8The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow...
CVE-2023-1120MEDIUM4.8The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow...
CVE-2023-0983MEDIUM6.1The stylish-cost-calculator-premium WordPress plugin before 7.9.0 does not sanitise and escape a parameter before output...
CVE-2023-0893MEDIUM4.8The Time Sheets WordPress plugin before 1.29.3 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-0874MEDIUM4.8The Klaviyo WordPress plugin before 3.0.10 does not sanitize and escape some of its settings, which could allow high-pri...
CVE-2023-0605MEDIUM4.8The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which c...
CVE-2023-0546MEDIUM5.4The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in ifr...
CVE-2023-0423MEDIUM4.8The WordPress Amazon S3 Plugin WordPress plugin before 1.6 does not sanitise and escape a parameter before outputting it...
CVE-2023-0422MEDIUM4.8The Article Directory WordPress plugin through 1.3 does not properly sanitize the `publish_terms_text` setting before di...
CVE-2023-0363MEDIUM5.4The Scheduled Announcements Widget WordPress plugin before 1.0 does not validate and escape some of its shortcode attrib...
CVE-2023-0157MEDIUM4.8The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting ...
CVE-2023-0156MEDIUM4.9The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings p...
CVE-2023-26860HIGH8.8SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges v...
CVE-2023-26788MEDIUM6.1Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause t...
CVE-2023-26774HIGH7.5An issue found in Sales Tracker Management System v.1.0 allows a remote attacker to access sensitive information via sal...
CVE-2023-29216CRITICAL9.8In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source a...
CVE-2023-29215CRITICAL9.8In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql ...
CVE-2023-27987CRITICAL9.1 In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy ...
CVE-2023-27603CRITICAL9.8 In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a...
CVE-2023-27602CRITICAL9.8In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files,...
CVE-2023-26120MEDIUM6.1This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-j...
CVE-2023-30456MEDIUM6.5An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency ...
CVE-2023-27720CRITICAL9.8D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows a...
CVE-2023-27719CRITICAL9.8D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now