2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3555 | MEDIUM | 6.1 | 0.4% | Jul 10, 2023 | A vulnerability was found in GZ Scripts PHP Vacation Rental Script 1.8. It has been classified as problematic. This affe... |
| CVE-2023-3554 | MEDIUM | 6.1 | 0.4% | Jul 10, 2023 | A vulnerability was found in GZ Scripts GZ Forum Script 1.8 and classified as problematic. Affected by this issue is som... |
| CVE-2023-3225 | MEDIUM | 4.8 | 0.5% | Jul 10, 2023 | The Float menu WordPress plugin before 5.0.3 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2023-3219 | MEDIUM | 5.3 | 6.1% | Jul 10, 2023 | The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax... |
| CVE-2023-3175 | MEDIUM | 4.8 | 0.5% | Jul 10, 2023 | The AI ChatBot WordPress plugin before 4.6.1 does not adequately escape some settings, allowing high-privilege users suc... |
| CVE-2023-3131 | MEDIUM | 4.3 | 0.5% | Jul 10, 2023 | The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, ... |
| CVE-2023-3129 | MEDIUM | 4.8 | 0.5% | Jul 10, 2023 | The URL Shortify WordPress plugin before 1.7.0 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2023-3118 | MEDIUM | 6.1 | 0.5% | Jul 10, 2023 | The Export All URLs WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting them back in ... |
| CVE-2023-37153 | MEDIUM | 6.1 | 0.6% | Jul 10, 2023 | KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation fe... |
| CVE-2023-37150 | MEDIUM | 6.1 | 0.5% | Jul 10, 2023 | Sourcecodester Online Pizza Ordering System v1.0 has a Cross-site scripting (XSS) vulnerability in "/admin/index.php?pag... |
| CVE-2023-36376 | MEDIUM | 4.8 | 0.5% | Jul 10, 2023 | Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scr... |
| CVE-2023-35887 | MEDIUM | 4.3 | 1.0% | Jul 10, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In ... |
| CVE-2023-35699 | MEDIUM | 4.6 | 0.2% | Jul 10, 2023 | Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device t... |
| CVE-2023-35698 | MEDIUM | 5.3 | 0.6% | Jul 10, 2023 | Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the F... |
| CVE-2023-2967 | MEDIUM | 4.8 | 0.5% | Jul 10, 2023 | The TinyMCE Custom Styles WordPress plugin before 1.1.4 does not sanitise and escape some of its settings, which could a... |
| CVE-2023-2964 | MEDIUM | 5.4 | 0.5% | Jul 10, 2023 | The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's conten... |
| CVE-2023-2853 | MEDIUM | 6.1 | 0.4% | Jul 10, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softmed SelfPatron... |
| CVE-2023-2796 | MEDIUM | 5.3 | 37.5% | Jul 10, 2023 | The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action... |
| CVE-2023-2709 | MEDIUM | 4.8 | 0.5% | Jul 10, 2023 | The AN_GradeBook WordPress plugin through 5.0.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2023-2635 | MEDIUM | 4.8 | 0.5% | Jul 10, 2023 | The Call Now Accessibility Button WordPress plugin before 1.1 does not sanitise and escape some of its settings, which c... |
| CVE-2023-2578 | MEDIUM | 4.8 | 0.5% | Jul 10, 2023 | The Buy Me a Coffee WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2023-2529 | MEDIUM | 5.4 | 0.5% | Jul 10, 2023 | The Enable SVG Uploads WordPress plugin through 2.1.5 does not sanitise uploaded SVG files, which could allow users with... |
| CVE-2023-2495 | MEDIUM | 4.3 | 0.3% | Jul 10, 2023 | The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyr... |
| CVE-2023-2029 | MEDIUM | 4.8 | 0.6% | Jul 10, 2023 | The PrePost SEO WordPress plugin through 3.0 does not properly sanitize some of its settings, which could allow high-pri... |
| CVE-2023-2028 | MEDIUM | 4.8 | 0.4% | Jul 10, 2023 | The Call Now Accessibility Button WordPress plugin before 1.1 does not properly sanitize some of its settings, which cou... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now