2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-25231CRITICAL9.8Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and ...
CVE-2023-24656HIGH8.8Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subj...
CVE-2023-24654HIGH8.8Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name...
CVE-2023-24653HIGH8.8Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldp...
CVE-2023-24652HIGH8.8Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Desc...
CVE-2023-24651MEDIUM5.4Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name...
CVE-2023-24364HIGH8.8Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the user...
CVE-2023-24251MEDIUM5.4WangEditor v5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /dist/index.js.
CVE-2023-23158MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to exec...
CVE-2023-23157MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to exec...
CVE-2023-23156CRITICAL9.8Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par...
CVE-2023-23155CRITICAL9.8Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the usernam...
CVE-2023-1070HIGH7.1External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.
CVE-2023-0552MEDIUM5.4The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in an...
CVE-2023-0548MEDIUM4.8The Namaste! LMS WordPress plugin before 2.5.9.4 does not sanitize and escape some of its settings, which could allow hi...
CVE-2023-0543MEDIUM4.8The Arigato Autoresponder and Newsletter WordPress plugin before 2.1.7.2 does not sanitize and escape some of its settin...
CVE-2023-0539MEDIUM5.4The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes bef...
CVE-2023-0535MEDIUM5.4The Donation Block For PayPal WordPress plugin before 2.1.0 does not validate and escape some of its shortcode attribute...
CVE-2023-0487HIGH7.2The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it i...
CVE-2023-0381HIGH8.8The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using ...
CVE-2023-0334MEDIUM6.1The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting ...
CVE-2023-0331HIGH7.5The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when gen...
CVE-2023-0279HIGH7.2The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using ...
CVE-2023-0278HIGH7.2The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a S...
CVE-2023-0230MEDIUM5.4The VK All in One Expansion Unit WordPress plugin before 9.86.0.0 does not validate and escape some of its block options...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now