2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41134MEDIUM5.3Authentication Bypass by Spoofing vulnerability in pluginkollektiv Antispam Bee allows Accessing Functionality Not Prope...
CVE-2023-40673MEDIUM6.5: Improper Control of Interaction Frequency vulnerability in cartpauj Cartpauj Register Captcha allows Functionality Mis...
CVE-2023-40557MEDIUM5.4Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in PickPlugins Tabs & Accord...
CVE-2023-40332CRITICAL9.8Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misu...
CVE-2023-39161MEDIUM5.4Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Discussion Board Discu...
CVE-2023-38520MEDIUM6.5External Control of Assumed-Immutable Web Parameter vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Funct...
CVE-2023-37865MEDIUM5.3Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Fun...
CVE-2023-34001MEDIUM5.3Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide M...
CVE-2023-33930HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Fr...
CVE-2023-28494MEDIUM4.3Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Cont...
CVE-2023-28492MEDIUM4.3Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue af...
CVE-2023-27460HIGH8.8Missing Authorization vulnerability in CodePeople, paypaldev CP Contact Form with Paypal allows Functionality Misuse.Thi...
CVE-2023-27437LOW3.7Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affe...
CVE-2023-26523MEDIUM4.3Missing Authorization vulnerability in CodePeople Calculated Fields Form allows Functionality Misuse.This issue affects ...
CVE-2023-26521MEDIUM4.3Missing Authorization vulnerability in CodePeople Search in Place allows Functionality Misuse.This issue affects Search ...
CVE-2023-24373CRITICAL9.8External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking Syst...
CVE-2023-23738MEDIUM5.3Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brai...
CVE-2023-23735MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brainstorm Force Spectra ...
CVE-2023-23730MEDIUM5.3Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstorm Force Spectra allows Functionality...
CVE-2023-52162MEDIUM6.7Mercusys MW325R EU V3 (Firmware MW325R(EU)_V3_1.11.0 Build 221019) is vulnerable to a stack-based buffer overflow, which...
CVE-2023-51219CRITICAL9.6A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controll...
CVE-2023-43556HIGH8.8Memory corruption in Hypervisor when platform information mentioned is not aligned.
CVE-2023-43555HIGH7.5Information disclosure in Video while parsing mp2 clip with invalid section length.
CVE-2023-43551HIGH7.5Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase a...
CVE-2023-43545HIGH7.8Memory corruption when more scan frequency list or channels are sent from the user space.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now