2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6633 | MEDIUM | 4.3 | 0.2% | Jan 29, 2024 | The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allo... |
| CVE-2023-6530 | MEDIUM | 5.4 | 0.4% | Jan 29, 2024 | The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before ou... |
| CVE-2023-6503 | MEDIUM | 5.4 | 0.2% | Jan 29, 2024 | The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation... |
| CVE-2023-6391 | HIGH | 8.8 | 0.3% | Jan 29, 2024 | The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which cou... |
| CVE-2023-6390 | HIGH | 8.8 | 0.3% | Jan 29, 2024 | The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which cou... |
| CVE-2023-6389 | MEDIUM | 6.1 | 25.7% | Jan 29, 2024 | The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it poss... |
| CVE-2023-6279 | HIGH | 7.1 | 0.5% | Jan 29, 2024 | The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any aut... |
| CVE-2023-6278 | MEDIUM | 6.1 | 0.4% | Jan 29, 2024 | The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and esc... |
| CVE-2023-6165 | MEDIUM | 4.8 | 0.4% | Jan 29, 2024 | The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings... |
| CVE-2023-5956 | MEDIUM | 4.8 | 0.4% | Jan 29, 2024 | The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2023-5943 | MEDIUM | 4.8 | 0.4% | Jan 29, 2024 | The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2023-5124 | MEDIUM | 4.8 | 0.4% | Jan 29, 2024 | The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from i... |
| CVE-2023-40548 | HIGH | 7.4 | 0.4% | Jan 29, 2024 | A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a ... |
| CVE-2023-29055 | HIGH | 7.5 | 1.1% | Jan 29, 2024 | In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.... |
| CVE-2023-5378 | MEDIUM | 5.4 | 0.5% | Jan 29, 2024 | Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This ... |
| CVE-2023-46838 | HIGH | 7.5 | 1.2% | Jan 29, 2024 | Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for ... |
| CVE-2023-46050 | — | — | — | Jan 29, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-45932 | — | — | — | Jan 29, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-45921 | — | — | — | Jan 29, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-45916 | — | — | — | Jan 29, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-6200 | HIGH | 7.5 | 2.1% | Jan 28, 2024 | A race condition was found in the Linux Kernel. Under certain conditions, an unauthenticated attacker from an adjacent n... |
| CVE-2023-48202 | MEDIUM | 5.4 | 0.4% | Jan 27, 2024 | Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate p... |
| CVE-2023-48201 | MEDIUM | 5.4 | 0.5% | Jan 27, 2024 | Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbit... |
| CVE-2023-6497 | MEDIUM | 4.8 | 0.3% | Jan 27, 2024 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic r... |
| CVE-2023-52389 | CRITICAL | 9.8 | 0.9% | Jan 27, 2024 | UTF32Encoding.cpp in POCO has a Poco::UTF32Encoding integer overflow and resultant stack buffer overflow because Poco::U... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now