2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-33524MEDIUM5.3Advent/SSC Inc. Tamale RMS < 23.1 is vulnerable to Directory Traversal. If one traverses to the affected URL, one enumer...
CVE-2023-3109MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository admidio/admidio prior to 4.2.8.
CVE-2023-33693MEDIUM5.5A buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) ...
CVE-2023-33690MEDIUM6.5SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special charac...
CVE-2023-33518MEDIUM5.3emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain...
CVE-2023-32766MEDIUM6.1Gitpod before 2022.11.3 allows XSS because redirection can occur for some protocols outside of the trusted set of three ...
CVE-2023-2634MEDIUM4.8The Get your number WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow ...
CVE-2023-2572MEDIUM6.1The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes...
CVE-2023-2571MEDIUM6.1The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes...
CVE-2023-2503MEDIUM6.1The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting i...
CVE-2023-2489MEDIUM4.8The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape...
CVE-2023-2488MEDIUM6.1The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape...
CVE-2023-2472MEDIUM6.1The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise...
CVE-2023-2337MEDIUM6.1The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, lead...
CVE-2023-2224MEDIUM4.8The SEO by 10Web WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-0545MEDIUM4.8The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2023-0152MEDIUM5.4The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes be...
CVE-2023-27989MEDIUM6.5A buffer overflow vulnerability in the CGI program of the Zyxel NR7101 firmware versions prior to V1.00(ABUV.8)C0 could...
CVE-2023-3064MEDIUM5.3Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2...
CVE-2023-34410MEDIUM5.3An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate valida...
CVE-2023-34408MEDIUM5.4DokuWiki before 2023-04-04a allows XSS via RSS titles.
CVE-2023-32334MEDIUM5.3IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL ...
CVE-2023-27861MEDIUM5.9IBM Maximo Application Suite - Manage Component 8.8.0 and 8.9.0 transmits sensitive information in cleartext that could ...
CVE-2023-3095MEDIUM6.5Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
CVE-2023-32582MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kyle Maurer Don8 plugin <= 0.4 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now