2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-21667MEDIUM6.5Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
CVE-2023-36307MEDIUM5.5ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField ...
CVE-2023-36308MEDIUM5.5disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Graysc...
CVE-2023-4636MEDIUM4.8The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i...
CVE-2023-29261MEDIUM5.5IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow a local user with specific information about the system to obtain ...
CVE-2023-22870MEDIUM5.9IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in...
CVE-2023-32338MEDIUM5.5IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in pla...
CVE-2023-41057MEDIUM5.5hyper-bump-it is a command line tool for updating the version in project files.`hyper-bump-it` reads a file glob pattern...
CVE-2023-41052MEDIUM5.3Vyper is a Pythonic Smart Contract Language. In affected versions the order of evaluation of the arguments of the builti...
CVE-2023-40015MEDIUM5.3Vyper is a Pythonic Smart Contract Language. For the following (probably non-exhaustive) list of expressions, the compil...
CVE-2023-4758MEDIUM5.5Buffer Over-read in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2023-4755MEDIUM5.5Use After Free in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2023-3221MEDIUM5.3User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacke...
CVE-2023-4587MEDIUM5.5An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local ...
CVE-2023-4298MEDIUM4.8The 123.chat WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2023-4284MEDIUM6.1The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back ...
CVE-2023-4269MEDIUM4.3The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowin...
CVE-2023-4254MEDIUM4.8The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high p...
CVE-2023-4253MEDIUM4.8The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high p...
CVE-2023-4151MEDIUM6.1The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back...
CVE-2023-4059MEDIUM4.3The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allow...
CVE-2023-40214MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vathemes Business Pro theme <= 1.10.4 versions.
CVE-2023-40205MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pixelgrade PixTypes plugin <= 1.4.15 versions.
CVE-2023-40197MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Devaldi Ltd flowpaper plugin <= 1.9.9 versions.
CVE-2023-40196MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now