2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-49515MEDIUM4.6Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allow...
CVE-2023-51807MEDIUM5.4Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafte...
CVE-2023-52068MEDIUM6.1kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.
CVE-2023-36236MEDIUM4.8Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via...
CVE-2023-48926MEDIUM5.3An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated a...
CVE-2023-5097MEDIUM5.5Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Wor...
CVE-2023-7234MEDIUM5.3 OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's se...
CVE-2023-4969MEDIUM6.5A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU me...
CVE-2023-7154MEDIUM4.8The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings,...
CVE-2023-7151MEDIUM6.1The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before o...
CVE-2023-7125MEDIUM4.3The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on t...
CVE-2023-7084MEDIUM5.4The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authen...
CVE-2023-7083MEDIUM5.4The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as w...
CVE-2023-6824MEDIUM6.5The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX act...
CVE-2023-6741MEDIUM4.3The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX act...
CVE-2023-6732MEDIUM4.8The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which c...
CVE-2023-6592MEDIUM5.3The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export fi...
CVE-2023-6292MEDIUM4.3The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its set...
CVE-2023-6046MEDIUM4.8The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privil...
CVE-2023-6005MEDIUM4.8The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of it...
CVE-2023-5558MEDIUM6.1The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the ...
CVE-2023-4757MEDIUM5.4The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape ...
CVE-2023-45231MEDIUM6.5EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing  Neighbor Discovery Redire...
CVE-2023-45229MEDIUM6.5EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option ...
CVE-2023-3771MEDIUM6.1The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now