2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48296MEDIUM4.3OroPlatform is a PHP Business Application Platform (BAP). Navigation history, most viewed and favorite navigation items...
CVE-2023-45824MEDIUM4.3OroPlatform is a PHP Business Application Platform (BAP). A logged in user can access page state data of pinned pages o...
CVE-2023-27608CRITICAL9.8Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Reward...
CVE-2023-25039HIGH8.8Missing Authorization vulnerability in CodePeople Google Maps CP.This issue affects Google Maps CP: from n/a through 1.0...
CVE-2023-22699MEDIUM5.4Missing Authorization vulnerability in MainWP MainWP Wordfence Extension.This issue affects MainWP Wordfence Extension: ...
CVE-2023-37886HIGH8.8Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.
CVE-2023-37885HIGH8.8Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.
CVE-2023-33923MEDIUM4.3Missing Authorization vulnerability in HashThemes Viral News, HashThemes Viral, HashThemes HashOne.This issue affects Vi...
CVE-2023-30480MEDIUM4.3Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5.
CVE-2023-5685HIGH7.5A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier st...
CVE-2023-4063MEDIUM5.3Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET ...
CVE-2023-23349LOW2.2Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recove...
CVE-2023-41099HIGH7.8In the Windows installer in Atos Eviden CardOS API before 5.5.5.2811, Local Privilege Escalation can occur.(from a regul...
CVE-2023-42954MEDIUM4.9A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websit...
CVE-2023-49837MEDIUM6.5Uncontrolled Resource Consumption vulnerability in David Artiss Code Embed.This issue affects Code Embed: from n/a throu...
CVE-2023-47715MEDIUM4.3IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to a...
CVE-2023-52620LOW2.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow timeout for anonymou...
CVE-2023-48903MEDIUM6.1Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers ...
CVE-2023-48902CRITICAL9.8An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate priv...
CVE-2023-48901CRITICAL9.8A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute...
CVE-2023-6500MEDIUM5.4The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco...
CVE-2023-49985MEDIUM6.5A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allo...
CVE-2023-49984MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 a...
CVE-2023-49983MEDIUM6.8A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allo...
CVE-2023-49982HIGH8.8Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now