2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0169MEDIUM5.4The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before output...
CVE-2023-0166MEDIUM5.4The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of i...
CVE-2023-0159HIGH7.5The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to ...
CVE-2023-0151MEDIUM5.4The uTubeVideo Gallery WordPress plugin before 2.0.8 does not validate and escape some of its shortcode attributes befor...
CVE-2023-0099MEDIUM6.1The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in ...
CVE-2023-0098HIGH8.8The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements ...
CVE-2023-0080HIGH8.8The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, wh...
CVE-2023-0075MEDIUM5.4The Amazon JS WordPress plugin through 0.10 does not validate and escape some of its shortcode attributes before outputt...
CVE-2023-0061MEDIUM5.4The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its sho...
CVE-2023-0060MEDIUM5.4The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes ...
CVE-2023-0034MEDIUM5.4The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attribute...
CVE-2023-0808MEDIUM6.8A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as pr...
CVE-2023-24572LOW3.3 Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerabil...
CVE-2023-23697LOW3.3Dell Command | Intel vPro Out of Band, versions before 4.4.0, contain an arbitrary folder delete vulnerability during un...
CVE-2023-25727MEDIUM5.4In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file...
CVE-2023-22367MEDIUM5.9Ichiran App for iOS versions prior to 3.1.0 and Ichiran App for Android versions prior to 3.1.0 improperly verify server...
CVE-2023-22362HIGH7.5SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a crede...
CVE-2023-22360HIGH7.8Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error han...
CVE-2023-22353HIGH7.8Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of da...
CVE-2023-22350HIGH7.8Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of da...
CVE-2023-22349HIGH7.8Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of da...
CVE-2023-22347HIGH7.8Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of da...
CVE-2023-22346HIGH7.8Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of da...
CVE-2023-22345HIGH7.8Out-of-bound write vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error...
CVE-2023-0680Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now