2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-24188CRITICAL9.1ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for ...
CVE-2023-24619MEDIUM5.5Redpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Acce...
CVE-2023-23553MEDIUM6.1 Control By Web X-400 devices are vulnerable to a cross-site scripting attack, which could result in private and session...
CVE-2023-23551CRITICAL9.8 Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to ...
CVE-2023-22854HIGH7.5The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated at...
CVE-2023-25159MEDIUM5.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is...
CVE-2023-24804MEDIUM4.4The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the a...
CVE-2023-23948MEDIUM5.5The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCl...
CVE-2023-0810MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.11.
CVE-2023-0405MEDIUM4.3The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin...
CVE-2023-0379MEDIUM5.4The Spotlight Social Feeds WordPress plugin before 1.4.3 does not validate and escape some of its block options before o...
CVE-2023-0373MEDIUM5.4The Lightweight Accordion WordPress plugin before 1.5.15 does not validate and escape some of its block options before o...
CVE-2023-0362MEDIUM5.4Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes befor...
CVE-2023-0360MEDIUM5.4The Location Weather WordPress plugin before 1.3.4 does not validate and escape some of its block options before outputt...
CVE-2023-0333MEDIUM5.4The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using ...
CVE-2023-0275MEDIUM5.4The Easy Accept Payments for PayPal WordPress plugin before 4.9.10 does not validate and escape some of its shortcode at...
CVE-2023-0270MEDIUM5.4The YaMaps for WordPress Plugin WordPress plugin before 0.6.26 does not validate and escape some of its shortcode attrib...
CVE-2023-0263HIGH8.8The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it ...
CVE-2023-0262HIGH8.8The WP Airbnb Review Slider WordPress plugin before 3.3 does not properly sanitise and escape a parameter before using i...
CVE-2023-0261HIGH8.8The WP TripAdvisor Review Slider WordPress plugin before 10.8 does not properly sanitise and escape a parameter before u...
CVE-2023-0260HIGH8.8The WP Review Slider WordPress plugin before 12.2 does not properly sanitise and escape a parameter before using it in a...
CVE-2023-0259HIGH8.8The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using ...
CVE-2023-0255HIGH8.8The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the si...
CVE-2023-0220HIGH8.8The Pinpoint Booking System WordPress plugin before 2.9.9.2.9 does not validate and escape one of its shortcode attribut...
CVE-2023-0177MEDIUM5.4The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortco...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now