2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-34461MEDIUM5.4PyBB is an open source bulletin board. A manual code review of the PyBB bulletin board server has revealed that a vulner...
CVE-2023-34167MEDIUM5.3Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-par...
CVE-2023-34160MEDIUM5.3Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-par...
CVE-2023-34158MEDIUM5.3Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-par...
CVE-2023-34156MEDIUM5.3Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnera...
CVE-2023-35779MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Seed Webs Seed Fonts plugin <= 2.3.1 versions.
CVE-2023-35776MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0...
CVE-2023-35775MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Backup Solutions WP Backup Manager plugin <= 1.13.1 ver...
CVE-2023-35772MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Alain Gonzalez Google Map Shortcode plugin <= 3.1.2 versio...
CVE-2023-3318MEDIUM5.4A vulnerability was found in SourceCodester Resort Management System 1.0. It has been declared as problematic. Affected ...
CVE-2023-33213MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Display Custom Fields – wpView plugin <= 1.3....
CVE-2023-3316MEDIUM6.5A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path tha...
CVE-2023-34415MEDIUM6.1When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox ...
CVE-2023-2899MEDIUM5.4The Google Map Shortcode WordPress plugin through 3.1.2 does not validate and escape some of its shortcode attributes be...
CVE-2023-2812MEDIUM4.8The Ultimate Dashboard WordPress plugin before 3.7.6 does not sanitise and escape some of its settings, which could allo...
CVE-2023-2811MEDIUM4.8The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow hi...
CVE-2023-2779MEDIUM6.1The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parame...
CVE-2023-2751MEDIUM5.3The Upload Resume WordPress plugin through 1.2.0 does not validate the captcha parameter when uploading a resume via the...
CVE-2023-2742MEDIUM4.8The AI ChatBot WordPress plugin before 4.5.5 does not sanitize and escape its settings, allowing high-privilege users su...
CVE-2023-2684MEDIUM4.8The File Renaming on Upload WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could...
CVE-2023-2654MEDIUM6.1The Conditional Menus WordPress plugin before 1.2.1 does not escape a parameter before outputting it back in an attribut...
CVE-2023-2600MEDIUM4.8The Custom Base Terms WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, which could allow...
CVE-2023-2527MEDIUM4.8The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and esca...
CVE-2023-2401MEDIUM4.8The QuBot WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could allow high privil...
CVE-2023-2399MEDIUM6.1The QuBot WordPress plugin before 1.1.6 doesn't filter user input on chat, leading to bad code inserted on it be reflect...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now