2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-7199 | MEDIUM | 5.3 | 0.6% | Jan 29, 2024 | The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthentica... |
| CVE-2023-7089 | MEDIUM | 5.4 | 0.4% | Jan 29, 2024 | The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a rol... |
| CVE-2023-6633 | MEDIUM | 4.3 | 0.2% | Jan 29, 2024 | The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allo... |
| CVE-2023-6530 | MEDIUM | 5.4 | 0.4% | Jan 29, 2024 | The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before ou... |
| CVE-2023-6503 | MEDIUM | 5.4 | 0.2% | Jan 29, 2024 | The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation... |
| CVE-2023-6389 | MEDIUM | 6.1 | 25.7% | Jan 29, 2024 | The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it poss... |
| CVE-2023-6278 | MEDIUM | 6.1 | 0.4% | Jan 29, 2024 | The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and esc... |
| CVE-2023-6165 | MEDIUM | 4.8 | 0.4% | Jan 29, 2024 | The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings... |
| CVE-2023-5956 | MEDIUM | 4.8 | 0.4% | Jan 29, 2024 | The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2023-5943 | MEDIUM | 4.8 | 0.4% | Jan 29, 2024 | The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2023-5124 | MEDIUM | 4.8 | 0.4% | Jan 29, 2024 | The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from i... |
| CVE-2023-5378 | MEDIUM | 5.4 | 0.5% | Jan 29, 2024 | Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This ... |
| CVE-2023-48202 | MEDIUM | 5.4 | 0.4% | Jan 27, 2024 | Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate p... |
| CVE-2023-48201 | MEDIUM | 5.4 | 0.5% | Jan 27, 2024 | Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbit... |
| CVE-2023-6497 | MEDIUM | 4.8 | 0.3% | Jan 27, 2024 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic r... |
| CVE-2023-6482 | MEDIUM | 5.2 | 0.1% | Jan 27, 2024 | Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a T... |
| CVE-2023-29081 | MEDIUM | 5.5 | 0.1% | Jan 26, 2024 | A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability... |
| CVE-2023-48129 | MEDIUM | 5.4 | 0.4% | Jan 26, 2024 | An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage ... |
| CVE-2023-48135 | MEDIUM | 5.4 | 0.4% | Jan 26, 2024 | An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage ... |
| CVE-2023-48133 | MEDIUM | 5.4 | 0.4% | Jan 26, 2024 | An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage o... |
| CVE-2023-48132 | MEDIUM | 5.4 | 0.4% | Jan 26, 2024 | An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious... |
| CVE-2023-48131 | MEDIUM | 5.4 | 0.4% | Jan 26, 2024 | An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leaka... |
| CVE-2023-48130 | MEDIUM | 5.4 | 0.4% | Jan 26, 2024 | An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of ... |
| CVE-2023-48128 | MEDIUM | 5.4 | 0.4% | Jan 26, 2024 | An issue in UNITED BOXING GYM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leak... |
| CVE-2023-48127 | MEDIUM | 5.4 | 0.4% | Jan 26, 2024 | An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of th... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now