2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5773Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-6136. Reason: This record is a reservatio...
CVE-2023-42363MEDIUM5.5A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.
CVE-2023-32062MEDIUM4.3OroPlatform is a package that assists system and user calendar management. Back-office users can access information from...
CVE-2023-49044CRITICAL9.8Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid p...
CVE-2023-49030HIGH7.5SQL Injection vulnerability in32ns KLive v.2019-1-19 and before allows a remote attacker to obtain sensitive information...
CVE-2023-48034MEDIUM6.1An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless key...
CVE-2023-49316HIGH7.5In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service.
CVE-2023-6329CRITICAL9.8An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll c...
CVE-2023-5974CRITICAL9.8The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parame...
CVE-2023-5958MEDIUM6.1The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the bac...
CVE-2023-5942MEDIUM5.4The Medialist WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputt...
CVE-2023-5906HIGH7.5The Job Manager & Career WordPress plugin before 1.4.4 contains a vulnerability in the Directory Listings system, which ...
CVE-2023-5845MEDIUM5.3The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthentic...
CVE-2023-5738MEDIUM5.4The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could...
CVE-2023-5737MEDIUM4.3The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users wit...
CVE-2023-5653MEDIUM6.1The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers bef...
CVE-2023-5641MEDIUM6.1The Martins Free & Easy SEO BackLink Link Building Network WordPress plugin before 1.2.30 does not sanitise and escape a...
CVE-2023-5620MEDIUM5.4The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of th...
CVE-2023-5611MEDIUM5.3The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting a...
CVE-2023-5604CRITICAL9.8The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administra...
CVE-2023-5560MEDIUM6.1The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputti...
CVE-2023-5559CRITICAL9.1The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing...
CVE-2023-5525MEDIUM4.3The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` A...
CVE-2023-5325MEDIUM6.1The Woocommerce Vietnam Checkout WordPress plugin before 2.0.6 does not escape the custom shipping phone field no the ch...
CVE-2023-5239HIGH7.5The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially un...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now