2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-4258MEDIUM6.5In Bluetooth mesh implementation If provisionee has a public key that is sent OOB then during provisioning it can be sen...
CVE-2023-43326MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exisits in multiple url of mooSocial v3.1.8 allows attackers to ste...
CVE-2023-43132MEDIUM6.5szvone vmqphp <=1.13 is vulnerable to SQL Injection. Unauthorized remote users can use sql injection attacks to obtain t...
CVE-2023-42426MEDIUM6.1Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary co...
CVE-2023-43458MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrar...
CVE-2023-43319MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arb...
CVE-2023-42817MEDIUM5.4Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from ...
CVE-2023-41871MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Poll Maker Team Poll Maker plugin <= 4.7.0 versions.
CVE-2023-41868MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ram Ratan Maurya, Codestag StagTools plugin <= 2.3.7 versi...
CVE-2023-41867MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AcyMailing Newsletter Team AcyMailing plugin <= 8.6.2 vers...
CVE-2023-41863MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Pepro Dev. Group PeproDev CF7 Database plugin <= 1.7.0 versio...
CVE-2023-5166MEDIUM6.5Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desk...
CVE-2023-5158MEDIUM5.5A flaw was found in vringh_kiov_advance in drivers/vhost/vringh.c in the host side of a virtio ring in the Linux Kernel....
CVE-2023-4892MEDIUM4.6Teedy v1.11 has a vulnerability in its text editor that allows events to be executed in HTML tags that an attacker coul...
CVE-2023-4631MEDIUM5.3The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of ...
CVE-2023-4549MEDIUM6.1The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For...
CVE-2023-4502MEDIUM4.8The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings,...
CVE-2023-4476MEDIUM6.1The Locatoraid Store Locator WordPress plugin before 3.9.24 does not sanitise and escape the lpr-search parameter before...
CVE-2023-4281MEDIUM5.3This Activity Log WordPress plugin before 2.8.8 retrieves client IP addresses from potentially untrusted headers, allowi...
CVE-2023-4148MEDIUM6.1The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputti...
CVE-2023-43339MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in cmsmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via...
CVE-2023-3226MEDIUM4.8The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow hig...
CVE-2023-43456MEDIUM5.4Cross Site Scripting vulnerability in Service Provider Management System v.1.0 allows a remote attacker to execute arbit...
CVE-2023-43256MEDIUM6.5A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the ...
CVE-2023-41295MEDIUM5.3Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerabili...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now