2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-37521MEDIUM5.3HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query st...
CVE-2023-2655HIGH7.2The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using i...
CVE-2023-2252LOW2.7The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file par...
CVE-2023-1405HIGH7.5The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform P...
CVE-2023-0824MEDIUM6.5The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missin...
CVE-2023-0769MEDIUM6.1The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting i...
CVE-2023-0479MEDIUM6.1The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoi...
CVE-2023-0389MEDIUM4.8The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which...
CVE-2023-0376MEDIUM5.4The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them b...
CVE-2023-0224CRITICAL9.8The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could...
CVE-2023-0094MEDIUM5.4The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes befo...
CVE-2023-0079MEDIUM5.4The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode a...
CVE-2023-6395CRITICAL9.8The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling ...
CVE-2023-52106CRITICAL9.1Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of...
CVE-2023-52105HIGH7.5The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect ava...
CVE-2023-52104HIGH7.5Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affe...
CVE-2023-52103CRITICAL9.8Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds r...
CVE-2023-52102HIGH7.5Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affe...
CVE-2023-52101CRITICAL9.1Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service a...
CVE-2023-52100HIGH7.5The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affec...
CVE-2023-52099HIGH7.5Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulne...
CVE-2023-34063HIGH8.3Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vu...
CVE-2023-52116HIGH7.5Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerabilit...
CVE-2023-52115HIGH7.5The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the...
CVE-2023-52114HIGH7.5Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now