2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6596HIGH7.5An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Contain...
CVE-2023-6544MEDIUM5.4A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filteri...
CVE-2023-6484MEDIUM5.3A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the...
CVE-2023-5675MEDIUM6.5A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the...
CVE-2023-3597MEDIUM5A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.aut...
CVE-2023-52220MEDIUM4.3Missing Authorization vulnerability in MonsterInsights Google Analytics by Monster Insights.This issue affects Google An...
CVE-2023-51484CRITICAL9.8Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.T...
CVE-2023-51482CRITICAL9.9Improper Authentication vulnerability in EazyPlugins Eazy Plugin Manager allows Accessing Functionality Not Properly Con...
CVE-2023-51478CRITICAL9.8Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Bu...
CVE-2023-6237MEDIUM5.9Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications tha...
CVE-2023-20249MEDIUM5.4A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow ...
CVE-2023-20248MEDIUM5.4A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow ...
CVE-2023-51477CRITICAL9.8Improper Authentication vulnerability in BUDDYBOSS DMCC BuddyBoss Theme allows Accessing Functionality Not Properly Cons...
CVE-2023-51472CRITICAL9.8Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation.This issue affect...
CVE-2023-51471HIGH8.2Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Accessing Functionality Not Properly C...
CVE-2023-51425CRITICAL9.8Improper Privilege Management vulnerability in Jacques Malgrange Rencontre – Dating Site allows Privilege Escalation.Thi...
CVE-2023-51405CRITICAL9.8Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Con...
CVE-2023-48763MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder ...
CVE-2023-47774MEDIUM5.4Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue ...
CVE-2023-47504CRITICAL9.8Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly...
CVE-2023-32127MEDIUM5.3Missing Authorization vulnerability in Daniel Powney Multi Rating allows Functionality Misuse.This issue affects Multi R...
CVE-2023-31090HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Fr...
CVE-2023-25790MEDIUM5.3Improper Authentication, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabil...
CVE-2023-25785MEDIUM5.3Missing Authorization vulnerability in Shoaib Saleem WP Post Rating allows Functionality Misuse.This issue affects WP Po...
CVE-2023-23989MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss Registra...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now