2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37521 | MEDIUM | 5.3 | 0.3% | Jan 16, 2024 | HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query st... |
| CVE-2023-2655 | HIGH | 7.2 | 0.9% | Jan 16, 2024 | The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using i... |
| CVE-2023-2252 | LOW | 2.7 | 1.3% | Jan 16, 2024 | The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file par... |
| CVE-2023-1405 | HIGH | 7.5 | 0.7% | Jan 16, 2024 | The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform P... |
| CVE-2023-0824 | MEDIUM | 6.5 | 0.3% | Jan 16, 2024 | The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missin... |
| CVE-2023-0769 | MEDIUM | 6.1 | 0.5% | Jan 16, 2024 | The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting i... |
| CVE-2023-0479 | MEDIUM | 6.1 | 0.5% | Jan 16, 2024 | The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoi... |
| CVE-2023-0389 | MEDIUM | 4.8 | 0.5% | Jan 16, 2024 | The Calculated Fields Form WordPress plugin before 1.1.151 does not sanitise and escape some of its form settings, which... |
| CVE-2023-0376 | MEDIUM | 5.4 | 0.7% | Jan 16, 2024 | The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them b... |
| CVE-2023-0224 | CRITICAL | 9.8 | 3.7% | Jan 16, 2024 | The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could... |
| CVE-2023-0094 | MEDIUM | 5.4 | 0.5% | Jan 16, 2024 | The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes befo... |
| CVE-2023-0079 | MEDIUM | 5.4 | 0.5% | Jan 16, 2024 | The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode a... |
| CVE-2023-6395 | CRITICAL | 9.8 | 1.6% | Jan 16, 2024 | The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling ... |
| CVE-2023-52106 | CRITICAL | 9.1 | 0.3% | Jan 16, 2024 | Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of... |
| CVE-2023-52105 | HIGH | 7.5 | 0.4% | Jan 16, 2024 | The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect ava... |
| CVE-2023-52104 | HIGH | 7.5 | 0.3% | Jan 16, 2024 | Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affe... |
| CVE-2023-52103 | CRITICAL | 9.8 | 0.5% | Jan 16, 2024 | Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds r... |
| CVE-2023-52102 | HIGH | 7.5 | 0.3% | Jan 16, 2024 | Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affe... |
| CVE-2023-52101 | CRITICAL | 9.1 | 0.4% | Jan 16, 2024 | Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service a... |
| CVE-2023-52100 | HIGH | 7.5 | 0.4% | Jan 16, 2024 | The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affec... |
| CVE-2023-52099 | HIGH | 7.5 | 0.3% | Jan 16, 2024 | Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulne... |
| CVE-2023-34063 | HIGH | 8.3 | 0.9% | Jan 16, 2024 | Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vu... |
| CVE-2023-52116 | HIGH | 7.5 | 0.4% | Jan 16, 2024 | Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerabilit... |
| CVE-2023-52115 | HIGH | 7.5 | 0.4% | Jan 16, 2024 | The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the... |
| CVE-2023-52114 | HIGH | 7.5 | 0.3% | Jan 16, 2024 | Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now