2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-5096MEDIUM5.4The HTML filter and csv-file search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '...
CVE-2023-5048MEDIUM5.4The WDContactFormBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Contact_Form_Builder...
CVE-2023-4726MEDIUM4.8The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions ...
CVE-2023-4686MEDIUM4.3The WP Customer Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and incl...
CVE-2023-48705MEDIUM5.4Nautobot is a Network Source of Truth and Network Automation Platform built as a web application All users of Nautobot v...
CVE-2023-2448MEDIUM5.3The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '...
CVE-2023-2438MEDIUM6.1The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. Th...
CVE-2023-47380MEDIUM6.1Admidio v4.2.12 and below is vulnerable to Cross Site Scripting (XSS).
CVE-2023-6253MEDIUM6A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to re...
CVE-2023-3103MEDIUM5.9Authentication bypass vulnerability, the exploitation of which could allow a local attacker to perform a Man-in-the-Midd...
CVE-2023-6189MEDIUM5.3Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and...
CVE-2023-6011MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DECE Software Geod...
CVE-2023-2447MEDIUM6.1The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th...
CVE-2023-2446MEDIUM6.5The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versio...
CVE-2023-47393MEDIUM5.3An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the maintenance orders of othe...
CVE-2023-47392MEDIUM5.3An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via s...
CVE-2023-41146MEDIUM4.3Autodesk Customer Support Portal allows cases created by users under an account to see cases created by other users on t...
CVE-2023-41145MEDIUM5.3Autodesk users who no longer have an active license for an account can still access cases for that account.
CVE-2023-48701MEDIUM6.1Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML file...
CVE-2023-48700MEDIUM6.5The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new ...
CVE-2023-48305MEDIUM4.4Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio...
CVE-2023-49104MEDIUM6.1An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able ...
CVE-2023-48304MEDIUM4.3Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio...
CVE-2023-48302MEDIUM5.4Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio...
CVE-2023-48301MEDIUM5.4Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now