2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-25928MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2023-0938CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown ...
CVE-2023-0936MEDIUM6.5A vulnerability was found in TP-Link Archer C50 V2_160801. It has been rated as problematic. Affected by this issue is s...
CVE-2023-0935CRITICAL9.8A vulnerability was found in DolphinPHP up to 1.5.1. It has been declared as critical. Affected by this vulnerability is...
CVE-2023-26267MEDIUM6.5php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML...
CVE-2023-0559MEDIUM5.4The GS Portfolio for Envato WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes ...
CVE-2023-0541MEDIUM5.4The GS Books Showcase WordPress plugin before 1.3.1 does not validate and escape some of its shortcode attributes before...
CVE-2023-0540MEDIUM5.4The GS Filterable Portfolio WordPress plugin before 1.6.1 does not validate and escape some of its shortcode attributes ...
CVE-2023-0492MEDIUM5.4The GS Products Slider for WooCommerce WordPress plugin before 1.5.9 does not validate and escape some of its shortcode ...
CVE-2023-0453MEDIUM4.3The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensu...
CVE-2023-0442MEDIUM6.1The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outpu...
CVE-2023-0429MEDIUM4.8The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape some of its settings, which could allow high ...
CVE-2023-0428MEDIUM6.1The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2023-0419MEDIUM5.4The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attribut...
CVE-2023-0380MEDIUM5.4The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before...
CVE-2023-0378MEDIUM5.4The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them...
CVE-2023-0375MEDIUM5.4The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before out...
CVE-2023-0372MEDIUM5.4The EmbedStories WordPress plugin before 0.7.5 does not validate and escape some of its shortcode attributes before outp...
CVE-2023-0371MEDIUM5.4The EmbedSocial WordPress plugin before 1.1.28 does not validate and escape some of its shortcode attributes before outp...
CVE-2023-0366MEDIUM5.4The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before o...
CVE-2023-0285MEDIUM5.4The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which coul...
CVE-2023-0271MEDIUM5.4The WP Font Awesome WordPress plugin before 1.7.9 does not validate and escape some of its shortcode attributes before o...
CVE-2023-0232CRITICAL9.8The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and ...
CVE-2023-0231MEDIUM5.4The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting th...
CVE-2023-0067MEDIUM5.4The Timed Content WordPress plugin before 2.73 does not validate and escape some of its shortcode attributes before outp...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now