2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-43481CRITICAL9.8An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote att...
CVE-2023-52075HIGH7.5ReVanced API proxies requests needed to feed the ReVanced Manager and website with data. Up to and including commit 71f8...
CVE-2023-40038HIGH8.8Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They...
CVE-2023-52077CRITICAL9.8Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allow...
CVE-2023-51700CRITICAL9.8Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your Wo...
CVE-2023-51697HIGH7.5Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenti...
CVE-2023-51665HIGH7.5Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenti...
CVE-2023-51664CRITICAL9.8tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/chan...
CVE-2023-51443MEDIUM5.9FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2023-50255HIGH7.8Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerab...
CVE-2023-7116CRITICAL9.8A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2.1.2. Affected by this issue ...
CVE-2023-4641MEDIUM5.5A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password ...
CVE-2023-3171HIGH7.5A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTabl...
CVE-2023-6190CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in İzmir Katip Çelebi Unive...
CVE-2023-52096HIGH7.5SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (su...
CVE-2023-49438MEDIUM6.1An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspectin...
CVE-2023-48003MEDIUM6.1An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redire...
CVE-2023-6268MEDIUM6.1The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting...
CVE-2023-6250HIGH7.5The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthe...
CVE-2023-6166MEDIUM6.1The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, lead...
CVE-2023-6155MEDIUM5.3The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX acti...
CVE-2023-6114HIGH7.5The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listin...
CVE-2023-5991CRITICAL9.8The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as do...
CVE-2023-5980MEDIUM4.8The BSK Forms Blacklist WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow...
CVE-2023-5939HIGH7.2The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now