2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-2978MEDIUM4.3A vulnerability was found in Abstrium Pydio Cells 4.2.0. It has been rated as problematic. Affected by this issue is som...
CVE-2023-2650MEDIUM6.5Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Imp...
CVE-2023-2973MEDIUM6.1A vulnerability, which was classified as problematic, has been found in SourceCodester Students Online Internship Timesh...
CVE-2023-2518MEDIUM6.1The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it...
CVE-2023-2470MEDIUM4.8The Add to Feedly WordPress plugin through 1.2.11 does not sanitize and escape its settings, allowing high-privilege use...
CVE-2023-2296MEDIUM6.1The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading t...
CVE-2023-2287MEDIUM4.3The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo imp...
CVE-2023-2256MEDIUM6.1The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL paramet...
CVE-2023-2223MEDIUM4.8The Login rebuilder WordPress plugin before 2.8.1 does not sanitise and escape some of its settings, which could allow h...
CVE-2023-2113MEDIUM4.8The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export,...
CVE-2023-2111MEDIUM4.9The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL quer...
CVE-2023-2023MEDIUM6.1The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading...
CVE-2023-1524MEDIUM6.5The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files....
CVE-2023-0733MEDIUM6.1The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow u...
CVE-2023-0443MEDIUM5.3The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker ...
CVE-2023-33955MEDIUM5.3Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the orig...
CVE-2023-33186MEDIUM6.1Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and ch...
CVE-2023-33183MEDIUM4.3Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the websi...
CVE-2023-2970MEDIUM6.5A vulnerability classified as problematic was found in MindSpore 2.0.0-alpha/2.0.0-rc1. This vulnerability affects the f...
CVE-2023-33182MEDIUM4.3Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsani...
CVE-2023-32685MEDIUM5.4Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements und...
CVE-2023-34204MEDIUM6.5imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these ar...
CVE-2023-32691MEDIUM5.9gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys sh...
CVE-2023-32687MEDIUM6.5tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instanc...
CVE-2023-32072MEDIUM4.8Tuleap is an open source tool for end to end traceability of application and system developments. Tuleap Community Editi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now