2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-52213MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate ...
CVE-2023-52203MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bas...
CVE-2023-51246MEDIUM5.4A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user ...
CVE-2023-6627MEDIUM6.1The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API r...
CVE-2023-6555MEDIUM6.1The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting i...
CVE-2023-6529MEDIUM6.1The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing un...
CVE-2023-6161MEDIUM6.1The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in ...
CVE-2023-6141MEDIUM5.4The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, whi...
CVE-2023-6139MEDIUM6.5The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, whi...
CVE-2023-5911MEDIUM4.8The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its se...
CVE-2023-1032MEDIUM5.5The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net...
CVE-2023-6552MEDIUM6.1Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerabil...
CVE-2023-5091MEDIUM5.5Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GP...
CVE-2023-41710MEDIUM5.4User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when addin...
CVE-2023-29052MEDIUM5.4Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitiz...
CVE-2023-29049MEDIUM6.1The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure us...
CVE-2023-7215MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Chanzhaoyu chatgpt-web 2.11.1. This issue affect...
CVE-2023-6801MEDIUM5.4The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2023-6798MEDIUM5.4The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2023-50121MEDIUM5.7Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).
CVE-2023-50609MEDIUM6.1Cross Site Scripting (XSS) vulnerability in AVA teaching video application service platform version 3.1, allows remote a...
CVE-2023-39853MEDIUM6.5SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the d...
CVE-2023-47559MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could al...
CVE-2023-46836MEDIUM4.7The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative Return Stack Overflow) are not IRQ-safe. It was ...
CVE-2023-46835MEDIUM5.5The current setup of the quarantine page tables assumes that the quarantine domain (dom_io) has been initialized with an...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now