2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27980HIGH8.8A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could...
CVE-2023-1543HIGH8.8Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1542MEDIUM5.4Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1541LOW3.8Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1540MEDIUM5.3Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1539MEDIUM5.3Improper Restriction of Excessive Authentication Attempts in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1538MEDIUM5.3Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1537CRITICAL9.8Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1536MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7.
CVE-2023-1535MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7.
CVE-2023-1527MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0.
CVE-2023-28425MEDIUM5.5Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticat...
CVE-2023-27578HIGH7.5Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05...
CVE-2023-0681MEDIUM6.1Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the abi...
CVE-2023-27586HIGH7.1CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to e...
CVE-2023-22288MEDIUM5.4HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticate...
CVE-2023-1517MEDIUM4.8Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.19.
CVE-2023-0940HIGH8.8The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not imple...
CVE-2023-0937MEDIUM6.1The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter ...
CVE-2023-0911MEDIUM6.5The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to ...
CVE-2023-0890MEDIUM6.5The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be di...
CVE-2023-0876MEDIUM6.1The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to m...
CVE-2023-0875HIGH8.8The WP Meta SEO WordPress plugin before 4.5.3 does not properly sanitize and escape inputs into SQL queries, leading to ...
CVE-2023-0865HIGH8.8The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to ...
CVE-2023-0631HIGH8.8The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that conc...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now