2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-21218CRITICAL9.8In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds ...
CVE-2023-21217CRITICAL9.8In PMRWritePMPageList of TBD, there is a possible out of bounds write due to an integer overflow. This could lead to loc...
CVE-2023-21216CRITICAL9.8In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after fre...
CVE-2023-21215CRITICAL9.8In DevmemIntAcquireRemoteCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition...
CVE-2023-21166CRITICAL9.8In RGXBackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lea...
CVE-2023-21164CRITICAL9.8In DevmemIntMapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This cou...
CVE-2023-21163CRITICAL9.8In PMR_ReadBytes of pmr.c, there is a possible arbitrary code execution due to a use after free. This could lead to loca...
CVE-2023-21162CRITICAL9.8In RGXUnbackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could l...
CVE-2023-6063HIGH7.5The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in ...
CVE-2023-5990MEDIUM6.5The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor WordPress plugin before 3.4.2 does not ...
CVE-2023-5979MEDIUM6.5The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin p...
CVE-2023-5953HIGH8.8The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have au...
CVE-2023-5952CRITICAL9.8The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtnia...
CVE-2023-5951MEDIUM6.1The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back ...
CVE-2023-5884MEDIUM6.5The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an u...
CVE-2023-5874MEDIUM4.8The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-5809MEDIUM4.8The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-5762HIGH8.8The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows t...
CVE-2023-5210MEDIUM6.1The AMP+ Plus WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2023-5141MEDIUM6.1The BSK Contact Form 7 Blacklist WordPress plugin through 1.0.1 does not sanitise and escape the inserted_count paramete...
CVE-2023-5137MEDIUM4.8The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which ...
CVE-2023-5108HIGH7.2The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before usin...
CVE-2023-5105MEDIUM6.5The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass ...
CVE-2023-4460MEDIUM5.4The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could a...
CVE-2023-49080MEDIUM4.3The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now