2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6633MEDIUM4.3The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allo...
CVE-2023-6530MEDIUM5.4The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before ou...
CVE-2023-6503MEDIUM5.4The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation...
CVE-2023-6391HIGH8.8The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which cou...
CVE-2023-6390HIGH8.8The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which cou...
CVE-2023-6389MEDIUM6.1The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it poss...
CVE-2023-6279HIGH7.1The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any aut...
CVE-2023-6278MEDIUM6.1The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and esc...
CVE-2023-6165MEDIUM4.8The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings...
CVE-2023-5956MEDIUM4.8The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-5943MEDIUM4.8The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high ...
CVE-2023-5124MEDIUM4.8The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from i...
CVE-2023-40548HIGH7.4A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a ...
CVE-2023-29055HIGH7.5In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin....
CVE-2023-5378MEDIUM5.4Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This ...
CVE-2023-46838HIGH7.5Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for ...
CVE-2023-46050Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-45932Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-45921Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-45916Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-6200HIGH7.5A race condition was found in the Linux Kernel. Under certain conditions, an unauthenticated attacker from an adjacent n...
CVE-2023-48202MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate p...
CVE-2023-48201MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbit...
CVE-2023-6497MEDIUM4.8The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic r...
CVE-2023-52389CRITICAL9.8UTF32Encoding.cpp in POCO has a Poco::UTF32Encoding integer overflow and resultant stack buffer overflow because Poco::U...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now