2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-4962MEDIUM5.4The Video PopUp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'video_popup' shortcode in version...
CVE-2023-4960MEDIUM5.4The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in ve...
CVE-2023-4372MEDIUM5.4The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in version...
CVE-2023-4248MEDIUM4.3The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th...
CVE-2023-4247MEDIUM5.4The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th...
CVE-2023-4246MEDIUM4.3The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th...
CVE-2023-37644MEDIUM5.5SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstr...
CVE-2023-6883MEDIUM4.3The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2023-6520MEDIUM4.3The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2023-6506MEDIUM4.3The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2023-6446MEDIUM4.8The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v...
CVE-2023-6223MEDIUM4.3The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi...
CVE-2023-6630MEDIUM4.3The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in al...
CVE-2023-52274MEDIUM6.1member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.
CVE-2023-45171MEDIUM5.5IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause...
CVE-2023-45169MEDIUM5.5IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel e...
CVE-2023-38267MEDIUM5.5IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security V...
CVE-2023-31001MEDIUM5.5IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security V...
CVE-2023-45175MEDIUM5.5IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel e...
CVE-2023-45173MEDIUM5.5IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel exte...
CVE-2023-49295MEDIUM6.5quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, RFC 9002) in Go. An attacker can cause its peer t...
CVE-2023-42941MEDIUM4.8The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker in a privileg...
CVE-2023-42934MEDIUM4.2An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, i...
CVE-2023-42929MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access prote...
CVE-2023-42872MEDIUM5.5The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now