2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-7228MEDIUM6.1The illi Link Party! WordPress plugin through 1.0 does not sanitise and escape some parameters, which could allow unauth...
CVE-2023-7196MEDIUM4.3The Ultimate Noindex Nofollow Tool WordPress plugin through 1.1.2 does not have CSRF check in place when updating its se...
CVE-2023-7195MEDIUM4.3The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which c...
CVE-2023-7168MEDIUM4.8The Better Follow Button for Jetpack WordPress plugin through 8.0 does not sanitise and escape some of its settings, whi...
CVE-2023-7088MEDIUM5.4The Add SVG Support for Media Uploader | inventivo WordPress plugin through 1.0.5 does not sanitize uploaded SVG files, ...
CVE-2023-7086MEDIUM5.4The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users wit...
CVE-2023-6786MEDIUM6.1The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirectin...
CVE-2023-6783MEDIUM4.8The WolfNet IDX for WordPress plugin through 1.19.1 does not sanitise and escape some of its settings, which could allow...
CVE-2023-6541MEDIUM6.1The Allow SVG WordPress plugin before 1.2.0 does not sanitize uploaded SVG files, which could allow users with a role as...
CVE-2023-6030MEDIUM5.4The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in ...
CVE-2023-5932MEDIUM4.8The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.14 does not sanitise and escape a paramete...
CVE-2023-5529MEDIUM4.8The Advanced Page Visit Counter WordPress plugin before 8.0.6 does not sanitise and escape some of its settings, which ...
CVE-2023-2334MEDIUM5.4The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress ...
CVE-2023-53146MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: dw2102: Fix null-ptr-deref in dw2102_i2c_tra...
CVE-2023-34732MEDIUM5.4An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c a...
CVE-2023-51328MEDIUM5.4PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "c_name, n...
CVE-2023-51295MEDIUM6.5PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin...
CVE-2023-7303MEDIUM5.1A vulnerability, which was classified as problematic, was found in q2apro q2apro-on-site-notifications up to 1.4.6. This...
CVE-2023-33770MEDIUM5.1Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at ...
CVE-2023-53144MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: erofs: fix wrong kunmap when using LZMA on HIGHMEM ...
CVE-2023-53143MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: fix another off-by-one fsmap error on 1k bloc...
CVE-2023-53141MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ila: do not generate empty messages in ila_xlat_nl_...
CVE-2023-53140MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: core: Remove the /proc/scsi/${proc_name} dire...
CVE-2023-53139MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfc: fdp: add null check of devm_kmalloc_array in f...
CVE-2023-53134MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Avoid order-5 memory allocation for TPA da...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now