2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-32489MEDIUM6.7 Dell PowerScale OneFS 8.2x -9.5x contains a privilege escalation vulnerability. A local attacker with high privileges c...
CVE-2023-32488MEDIUM4.3 Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacke...
CVE-2023-32494MEDIUM6.7 Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local pr...
CVE-2023-4381MEDIUM4.3Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-2272MEDIUM6.1The Tiempo.com WordPress plugin through 0.1.2 does not sanitise and escape the page parameter before outputting it back ...
CVE-2023-2271MEDIUM4.3The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when deleting its shortcode, which could allow at...
CVE-2023-2254MEDIUM4.8The Ko-fi Button WordPress plugin before 1.3.3 does not properly some of its settings, which could allow high-privilege ...
CVE-2023-2225MEDIUM4.8The SEO ALert WordPress plugin through 1.59 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-2123MEDIUM6.1The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it ...
CVE-2023-2122MEDIUM6.1The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter ...
CVE-2023-1465MEDIUM6.1The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, lea...
CVE-2023-1110MEDIUM5.4The Yellow Yard Searchbar WordPress plugin before 2.8.12 does not validate and escape some of its shortcode attributes b...
CVE-2023-0551MEDIUM5.4The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action...
CVE-2023-0274MEDIUM5.4The URL Params WordPress plugin before 2.5 does not validate and escape some of its shortcode attributes before outputti...
CVE-2023-0058MEDIUM6.1The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when creating and editing its shortcode, and is m...
CVE-2023-30871MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PT Woo Plugins (by Webdados) Stock Exporter for WooCommerc...
CVE-2023-30779MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jonathan Daggerhart Query Wrangler plugin <= 1.5.51 versio...
CVE-2023-30786MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Benjamin Guy Captcha Them All plugin <= 1.3.3 versions...
CVE-2023-30785MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Video Grid plugin <= 1.21 versions...
CVE-2023-30784MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kaya Studio Kaya QR Code Generator plugin <= 1.5...
CVE-2023-30782MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions.
CVE-2023-30473MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov YML for Yandex Market plugin <= 3.10.7 vers...
CVE-2023-39507MEDIUM6.1Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a...
CVE-2023-4374MEDIUM4.3The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a...
CVE-2023-3958MEDIUM5.4The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now