2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49803HIGH7.5@koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to version 5.0.0...
CVE-2023-49802MEDIUM6.1The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-d...
CVE-2023-45292MEDIUM5.3When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the fi...
CVE-2023-49796MEDIUM5.3MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a limited file wr...
CVE-2023-49494MEDIUM6.1DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component selec...
CVE-2023-49490MEDIUM6.1XunRuiCMS v4.5.5 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admi...
CVE-2023-49488MEDIUM6.1A cross-site scripting (XSS) vulnerability in Openfiler ESA v2.99.1 allows attackers to execute arbitrary web scripts or...
CVE-2023-6035HIGH8.8The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an ...
CVE-2023-5955MEDIUM4.8The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could all...
CVE-2023-5940MEDIUM4.8The WP Not Login Hide (WPNLH) WordPress plugin through 1.0 does not sanitise and escape some of its settings, which coul...
CVE-2023-5907MEDIUM6.5The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrat...
CVE-2023-5757MEDIUM4.8The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow h...
CVE-2023-5750MEDIUM6.1The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2023-5749MEDIUM6.1The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the pa...
CVE-2023-6679MEDIUM5.5A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Di...
CVE-2023-49795MEDIUM5.3MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side req...
CVE-2023-48715MEDIUM5.4Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.2.9...
CVE-2023-6538MEDIUM6.5SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authe...
CVE-2023-6671HIGH8.8A vulnerability has been discovered on OJS, that consists in a CSRF (Cross-Site Request Forgery) attack that forces an e...
CVE-2023-6194HIGH7.1In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document typ...
CVE-2023-49418CRITICAL9.8TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules.
CVE-2023-49417CRITICAL9.8TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg.
CVE-2023-6186HIGH8.8Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in m...
CVE-2023-6185HIGH8.8Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attack...
CVE-2023-49964HIGH8.8An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now