2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-46471MEDIUM5.4Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbi...
CVE-2023-46470MEDIUM5.4Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbi...
CVE-2023-47417MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the component /shells/embedder.html of DZSlides after v2011.07.25 allows att...
CVE-2023-5799MEDIUM5.4The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing ...
CVE-2023-5651MEDIUM5.4The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensu...
CVE-2023-5610MEDIUM5.4The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user ...
CVE-2023-5609MEDIUM6.1The Seraphinite Accelerator WordPress plugin before 2.2.29 does not sanitise and escape a parameter before outputting it...
CVE-2023-5509MEDIUM5.4The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in use...
CVE-2023-5343MEDIUM4.8The Popup box WordPress plugin before 3.7.9 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-5140MEDIUM6.1The Bonus for Woo WordPress plugin before 5.8.3 does not sanitise and escape some parameters before outputting them back...
CVE-2023-5119MEDIUM4.8The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission s...
CVE-2023-4970MEDIUM4.8The PubyDoc WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2023-4808MEDIUM4.8The WP Post Popup WordPress plugin through 3.7.3 does not sanitise and escape some of its inputs, which could allow high...
CVE-2023-4799MEDIUM5.4The Magic Embeds WordPress plugin before 3.1.2 does not validate and escape some of its shortcode attributes before outp...
CVE-2023-48309MEDIUM5.3NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the defau...
CVE-2023-48300MEDIUM5.4The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored ...
CVE-2023-38883MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic all...
CVE-2023-38882MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic all...
CVE-2023-38881MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic all...
CVE-2023-48223MEDIUM5.9fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does not proper...
CVE-2023-48218MEDIUM5.3The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3....
CVE-2023-36013MEDIUM6.5PowerShell Information Disclosure Vulnerability
CVE-2023-6197MEDIUM5.4The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2023-48039MEDIUM5.5GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leak in gf_mpd_parse_string media_tools/mpd.c:75.
CVE-2023-47772MEDIUM5.4Contributor+ Stored Cross-Site Scripting (XSS) vulnerability in Slider Revolution <= 6.6.14.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now