2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-52213 | MEDIUM | 6.1 | 0.3% | Jan 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate ... |
| CVE-2023-52203 | MEDIUM | 4.8 | 0.3% | Jan 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bas... |
| CVE-2023-51246 | MEDIUM | 5.4 | 0.3% | Jan 8, 2024 | A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user ... |
| CVE-2023-6627 | MEDIUM | 6.1 | 0.6% | Jan 8, 2024 | The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API r... |
| CVE-2023-6555 | MEDIUM | 6.1 | 0.4% | Jan 8, 2024 | The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting i... |
| CVE-2023-6529 | MEDIUM | 6.1 | 0.2% | Jan 8, 2024 | The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing un... |
| CVE-2023-6161 | MEDIUM | 6.1 | 0.4% | Jan 8, 2024 | The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2023-6141 | MEDIUM | 5.4 | 0.4% | Jan 8, 2024 | The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, whi... |
| CVE-2023-6139 | MEDIUM | 6.5 | 0.6% | Jan 8, 2024 | The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, whi... |
| CVE-2023-5911 | MEDIUM | 4.8 | 0.3% | Jan 8, 2024 | The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its se... |
| CVE-2023-1032 | MEDIUM | 5.5 | 0.3% | Jan 8, 2024 | The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net... |
| CVE-2023-6552 | MEDIUM | 6.1 | 0.5% | Jan 8, 2024 | Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerabil... |
| CVE-2023-5091 | MEDIUM | 5.5 | 0.2% | Jan 8, 2024 | Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GP... |
| CVE-2023-41710 | MEDIUM | 5.4 | 0.4% | Jan 8, 2024 | User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when addin... |
| CVE-2023-29052 | MEDIUM | 5.4 | 0.4% | Jan 8, 2024 | Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitiz... |
| CVE-2023-29049 | MEDIUM | 6.1 | 0.6% | Jan 8, 2024 | The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure us... |
| CVE-2023-7215 | MEDIUM | 6.1 | 0.5% | Jan 8, 2024 | A vulnerability, which was classified as problematic, has been found in Chanzhaoyu chatgpt-web 2.11.1. This issue affect... |
| CVE-2023-6801 | MEDIUM | 5.4 | 0.3% | Jan 6, 2024 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is... |
| CVE-2023-6798 | MEDIUM | 5.4 | 0.3% | Jan 6, 2024 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is... |
| CVE-2023-50121 | MEDIUM | 5.7 | 0.4% | Jan 6, 2024 | Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS). |
| CVE-2023-50609 | MEDIUM | 6.1 | 0.5% | Jan 6, 2024 | Cross Site Scripting (XSS) vulnerability in AVA teaching video application service platform version 3.1, allows remote a... |
| CVE-2023-39853 | MEDIUM | 6.5 | 0.7% | Jan 6, 2024 | SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the d... |
| CVE-2023-47559 | MEDIUM | 5.4 | 0.3% | Jan 5, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could al... |
| CVE-2023-46836 | MEDIUM | 4.7 | 0.3% | Jan 5, 2024 | The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative Return Stack Overflow) are not IRQ-safe. It was ... |
| CVE-2023-46835 | MEDIUM | 5.5 | 0.3% | Jan 5, 2024 | The current setup of the quarantine page tables assumes that the quarantine domain (dom_io) has been initialized with an... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now