2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5209MEDIUM4.8The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its...
CVE-2023-4922CRITICAL9.8The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter.
CVE-2023-4642MEDIUM5.9The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple ...
CVE-2023-4514MEDIUM5.4The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes befo...
CVE-2023-4297MEDIUM4.3The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing ...
CVE-2023-4252MEDIUM5.3The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attack...
CVE-2023-49047HIGH7.5Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName.
CVE-2023-49042CRITICAL9.8Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedSt...
CVE-2023-49040CRITICAL9.8An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the f...
CVE-2023-49028MEDIUM5.4Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitra...
CVE-2023-42000CRITICAL9.8Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServl...
CVE-2023-41999CRITICAL9.8An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a v...
CVE-2023-41998CRITICAL9.8Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. ...
CVE-2023-2707MEDIUM4.8The gAppointments WordPress plugin through 1.9.5.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2023-49046CRITICAL9.8Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devNam...
CVE-2023-49043CRITICAL9.8Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpaps...
CVE-2023-49029MEDIUM6.1Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitra...
CVE-2023-41257HIGH8.8A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially ...
CVE-2023-40194HIGH8.8An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due ...
CVE-2023-39542HIGH8.8A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted mal...
CVE-2023-38573HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field. A specially crafte...
CVE-2023-35985HIGH8.8An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due ...
CVE-2023-32616HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles 3D annotations. A specially crafted J...
CVE-2023-31275HIGH7.8An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elem...
CVE-2023-6287MEDIUM5.5Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now