2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25231 | CRITICAL | 9.8 | 1.0% | Feb 27, 2023 | Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and ... |
| CVE-2023-24656 | HIGH | 8.8 | 1.0% | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subj... |
| CVE-2023-24654 | HIGH | 8.8 | 1.0% | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name... |
| CVE-2023-24653 | HIGH | 8.8 | 1.0% | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldp... |
| CVE-2023-24652 | HIGH | 8.8 | 1.0% | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Desc... |
| CVE-2023-24651 | MEDIUM | 5.4 | 0.6% | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name... |
| CVE-2023-24364 | HIGH | 8.8 | 1.0% | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the user... |
| CVE-2023-24251 | MEDIUM | 5.4 | 0.4% | Feb 27, 2023 | WangEditor v5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /dist/index.js. |
| CVE-2023-23158 | MEDIUM | 5.4 | 0.6% | Feb 27, 2023 | A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to exec... |
| CVE-2023-23157 | MEDIUM | 5.4 | 0.6% | Feb 27, 2023 | A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to exec... |
| CVE-2023-23156 | CRITICAL | 9.8 | 3.7% | Feb 27, 2023 | Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par... |
| CVE-2023-23155 | CRITICAL | 9.8 | 1.1% | Feb 27, 2023 | Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the usernam... |
| CVE-2023-1070 | HIGH | 7.1 | 0.8% | Feb 27, 2023 | External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. |
| CVE-2023-0552 | MEDIUM | 5.4 | 24.3% | Feb 27, 2023 | The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in an... |
| CVE-2023-0548 | MEDIUM | 4.8 | 0.5% | Feb 27, 2023 | The Namaste! LMS WordPress plugin before 2.5.9.4 does not sanitize and escape some of its settings, which could allow hi... |
| CVE-2023-0543 | MEDIUM | 4.8 | 0.5% | Feb 27, 2023 | The Arigato Autoresponder and Newsletter WordPress plugin before 2.1.7.2 does not sanitize and escape some of its settin... |
| CVE-2023-0539 | MEDIUM | 5.4 | 0.5% | Feb 27, 2023 | The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes bef... |
| CVE-2023-0535 | MEDIUM | 5.4 | 0.5% | Feb 27, 2023 | The Donation Block For PayPal WordPress plugin before 2.1.0 does not validate and escape some of its shortcode attribute... |
| CVE-2023-0487 | HIGH | 7.2 | 1.5% | Feb 27, 2023 | The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it i... |
| CVE-2023-0381 | HIGH | 8.8 | 1.3% | Feb 27, 2023 | The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using ... |
| CVE-2023-0334 | MEDIUM | 6.1 | 0.9% | Feb 27, 2023 | The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting ... |
| CVE-2023-0331 | HIGH | 7.5 | 0.8% | Feb 27, 2023 | The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when gen... |
| CVE-2023-0279 | HIGH | 7.2 | 0.8% | Feb 27, 2023 | The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using ... |
| CVE-2023-0278 | HIGH | 7.2 | 0.8% | Feb 27, 2023 | The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a S... |
| CVE-2023-0230 | MEDIUM | 5.4 | 0.6% | Feb 27, 2023 | The VK All in One Expansion Unit WordPress plugin before 9.86.0.0 does not validate and escape some of its block options... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now