2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-3647MEDIUM4.8The IURNY by INDIGITALL WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could all...
CVE-2023-3372MEDIUM5.4The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before o...
CVE-2023-3178MEDIUM4.3The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could al...
CVE-2023-37521MEDIUM5.3HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query st...
CVE-2023-0824MEDIUM6.5The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missin...
CVE-2023-0769MEDIUM6.1The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting i...
CVE-2023-0479MEDIUM6.1The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoi...
CVE-2023-0389MEDIUM4.8The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which...
CVE-2023-0376MEDIUM5.4The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them b...
CVE-2023-0094MEDIUM5.4The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes befo...
CVE-2023-0079MEDIUM5.4The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode a...
CVE-2023-52112MEDIUM5.3Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability ma...
CVE-2023-48104MEDIUM6.1Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.
CVE-2023-47459MEDIUM6.5An issue in Knovos Discovery v.22.67.0 allows a remote attacker to obtain sensitive information via the /DiscoveryReview...
CVE-2023-41619MEDIUM6.1Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article....
CVE-2023-6941MEDIUM4.8The Keap Official Opt-in Forms WordPress plugin through 1.0.11 does not sanitise and escape some of its settings, which ...
CVE-2023-6843MEDIUM4.3The easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg WordPress p...
CVE-2023-6163MEDIUM4.8The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow ...
CVE-2023-6066MEDIUM4.3The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of i...
CVE-2023-6050MEDIUM6.1The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generat...
CVE-2023-6048MEDIUM6.5The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like...
CVE-2023-4925MEDIUM4.8The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which co...
CVE-2023-42135MEDIUM6.8PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via ...
CVE-2023-42134MEDIUM6.8PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partitio...
CVE-2023-4001MEDIUM6.8An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the con...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now