2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-7199MEDIUM5.3The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthentica...
CVE-2023-7089MEDIUM5.4The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a rol...
CVE-2023-6633MEDIUM4.3The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allo...
CVE-2023-6530MEDIUM5.4The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before ou...
CVE-2023-6503MEDIUM5.4The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation...
CVE-2023-6389MEDIUM6.1The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it poss...
CVE-2023-6278MEDIUM6.1The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and esc...
CVE-2023-6165MEDIUM4.8The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings...
CVE-2023-5956MEDIUM4.8The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-5943MEDIUM4.8The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high ...
CVE-2023-5124MEDIUM4.8The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from i...
CVE-2023-5378MEDIUM5.4Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This ...
CVE-2023-48202MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate p...
CVE-2023-48201MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbit...
CVE-2023-6497MEDIUM4.8The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic r...
CVE-2023-6482MEDIUM5.2Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a T...
CVE-2023-29081MEDIUM5.5A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability...
CVE-2023-48129MEDIUM5.4An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage ...
CVE-2023-48135MEDIUM5.4An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage ...
CVE-2023-48133MEDIUM5.4An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage o...
CVE-2023-48132MEDIUM5.4An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious...
CVE-2023-48131MEDIUM5.4An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leaka...
CVE-2023-48130MEDIUM5.4An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of ...
CVE-2023-48128MEDIUM5.4An issue in UNITED BOXING GYM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leak...
CVE-2023-48127MEDIUM5.4An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of th...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now