2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-46755MEDIUM5.3Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerabilit...
CVE-2023-46483MEDIUM5.4Cross Site Scripting vulnerability in timetec AWDMS v.2.0 allows an attacker to obtain sensitive information via a craft...
CVE-2023-41270MEDIUM4.3Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Smart TV UE40D7000 version T-GAPDEUC-...
CVE-2023-4061MEDIUM6.5A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possib...
CVE-2023-6002MEDIUM6.1YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files ca...
CVE-2023-46001MEDIUM5.5Buffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denia...
CVE-2023-5982MEDIUM5.4The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2023-5819MEDIUM4.8The Amazonify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to...
CVE-2023-5818MEDIUM4.3The Amazonify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8...
CVE-2023-4956MEDIUM4.3A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user in...
CVE-2023-4154MEDIUM6.5A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directo...
CVE-2023-46252MEDIUM6.1Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in ...
CVE-2023-46744MEDIUM5.4Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (X...
CVE-2023-46737MEDIUM5.3Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker contro...
CVE-2023-32966MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab Jazz Popups leads to Stored XSS.This issue affects Jazz Popup...
CVE-2023-28499MEDIUM5.4Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML...
CVE-2023-4272MEDIUM5.5A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory. ...
CVE-2023-41425MEDIUM6.1Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code...
CVE-2023-5709MEDIUM6.5The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a...
CVE-2023-5703MEDIUM5.4The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2023-5669MEDIUM5.4The Featured Image Caption plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode ...
CVE-2023-5661MEDIUM5.4The Social Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialfeed' shortcod...
CVE-2023-5660MEDIUM5.4The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s...
CVE-2023-5659MEDIUM5.4The Interact: Embed A Quiz On Your Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2023-5577MEDIUM5.4The Bitly's plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpbitly' shortcode in al...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now