2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32872MEDIUM6.7In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio...
CVE-2023-32831MEDIUM5.5In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local infor...
CVE-2023-50096HIGH7.5STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read...
CVE-2023-50094HIGH8.8reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacha...
CVE-2023-6485MEDIUM5.4The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which co...
CVE-2023-6421HIGH7.5The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receivin...
CVE-2023-6271HIGH7.5The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-acce...
CVE-2023-6113HIGH7.5The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not preve...
CVE-2023-6064HIGH7.5The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containin...
CVE-2023-6037MEDIUM4.8The WP TripAdvisor Review Slider WordPress plugin before 11.9 does not sanitise and escape some of its settings, which c...
CVE-2023-6000MEDIUM6.1The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and inje...
CVE-2023-5877CRITICAL9.8The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliat...
CVE-2023-52133HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhileTrue Most And...
CVE-2023-52132HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jewel Theme WP Adm...
CVE-2023-52131HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Zinc Page Gener...
CVE-2023-51547HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPManageNinja LLC ...
CVE-2023-51503HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Bui...
CVE-2023-51469CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestres do WP Chec...
CVE-2023-51423CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team W...
CVE-2023-7193HIGH8.1A vulnerability was found in MTab Bookmark up to 1.2.6 and classified as critical. This issue affects some unknown proce...
CVE-2023-52185HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Everestthemes Everest Backup – WordPress Clo...
CVE-2023-52134HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eyal Fitoussi GEO ...
CVE-2023-7191HIGH8.8A vulnerability, which was classified as critical, was found in S-CMS up to 2.0_build20220529-20231006. This affects an ...
CVE-2023-7190HIGH8.8A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006. Affected by...
CVE-2023-7189HIGH8.8A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006. Affected by this vulnerabili...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now