2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-3555MEDIUM6.1A vulnerability was found in GZ Scripts PHP Vacation Rental Script 1.8. It has been classified as problematic. This affe...
CVE-2023-3554MEDIUM6.1A vulnerability was found in GZ Scripts GZ Forum Script 1.8 and classified as problematic. Affected by this issue is som...
CVE-2023-3225MEDIUM4.8The Float menu WordPress plugin before 5.0.3 does not sanitise and escape some of its settings, which could allow high p...
CVE-2023-3219MEDIUM5.3The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax...
CVE-2023-3175MEDIUM4.8The AI ChatBot WordPress plugin before 4.6.1 does not adequately escape some settings, allowing high-privilege users suc...
CVE-2023-3131MEDIUM4.3The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, ...
CVE-2023-3129MEDIUM4.8The URL Shortify WordPress plugin before 1.7.0 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-3118MEDIUM6.1The Export All URLs WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting them back in ...
CVE-2023-37153MEDIUM6.1KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation fe...
CVE-2023-37150MEDIUM6.1Sourcecodester Online Pizza Ordering System v1.0 has a Cross-site scripting (XSS) vulnerability in "/admin/index.php?pag...
CVE-2023-36376MEDIUM4.8Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scr...
CVE-2023-35887MEDIUM4.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In ...
CVE-2023-35699MEDIUM4.6Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device t...
CVE-2023-35698MEDIUM5.3Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the F...
CVE-2023-2967MEDIUM4.8The TinyMCE Custom Styles WordPress plugin before 1.1.4 does not sanitise and escape some of its settings, which could a...
CVE-2023-2964MEDIUM5.4The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's conten...
CVE-2023-2853MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softmed SelfPatron...
CVE-2023-2796MEDIUM5.3The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action...
CVE-2023-2709MEDIUM4.8The AN_GradeBook WordPress plugin through 5.0.1 does not sanitise and escape some of its settings, which could allow hig...
CVE-2023-2635MEDIUM4.8The Call Now Accessibility Button WordPress plugin before 1.1 does not sanitise and escape some of its settings, which c...
CVE-2023-2578MEDIUM4.8The Buy Me a Coffee WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow hig...
CVE-2023-2529MEDIUM5.4The Enable SVG Uploads WordPress plugin through 2.1.5 does not sanitise uploaded SVG files, which could allow users with...
CVE-2023-2495MEDIUM4.3The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyr...
CVE-2023-2029MEDIUM4.8The PrePost SEO WordPress plugin through 3.0 does not properly sanitize some of its settings, which could allow high-pri...
CVE-2023-2028MEDIUM4.8The Call Now Accessibility Button WordPress plugin before 1.1 does not properly sanitize some of its settings, which cou...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now