2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-5611MEDIUM5.3The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting a...
CVE-2023-5560MEDIUM6.1The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputti...
CVE-2023-5525MEDIUM4.3The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` A...
CVE-2023-5325MEDIUM6.1The Woocommerce Vietnam Checkout WordPress plugin before 2.0.6 does not escape the custom shipping phone field no the ch...
CVE-2023-5209MEDIUM4.8The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its...
CVE-2023-4642MEDIUM5.9The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple ...
CVE-2023-4514MEDIUM5.4The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes befo...
CVE-2023-4297MEDIUM4.3The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing ...
CVE-2023-4252MEDIUM5.3The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attack...
CVE-2023-49028MEDIUM5.4Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitra...
CVE-2023-2707MEDIUM4.8The gAppointments WordPress plugin through 1.9.5.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2023-49029MEDIUM6.1Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitra...
CVE-2023-6287MEDIUM5.5Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords...
CVE-2023-5871MEDIUM5.3A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such a...
CVE-2023-43701MEDIUM5.4Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious acto...
CVE-2023-42501MEDIUM4.3Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and ...
CVE-2023-6202MEDIUM4.3Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker w...
CVE-2023-48369MEDIUM5.3Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to differe...
CVE-2023-47168MEDIUM6.1Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user cli...
CVE-2023-45223MEDIUM4.3Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a me...
CVE-2023-43754MEDIUM4.3Mattermost fails to check whether the  “Allow users to view archived channels”  setting is enabled during permalink prev...
CVE-2023-35075MEDIUM5.4Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowi...
CVE-2023-47865MEDIUM4.3Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. ...
CVE-2023-25632MEDIUM5.5The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open ...
CVE-2023-6313MEDIUM6.1A vulnerability was found in SourceCodester URL Shortener 1.0. It has been declared as problematic. Affected by this vul...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now