2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-20703MEDIUM5.5In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl...
CVE-2023-20701MEDIUM6.7In widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privil...
CVE-2023-20700MEDIUM6.7In widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privil...
CVE-2023-20699MEDIUM6.7In adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...
CVE-2023-20698MEDIUM4.4In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio...
CVE-2023-20697MEDIUM4.4In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio...
CVE-2023-20696MEDIUM6.7In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation...
CVE-2023-20695MEDIUM6.7In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation...
CVE-2023-20694MEDIUM6.7In preloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation...
CVE-2023-20673MEDIUM6.7In vcu, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege wi...
CVE-2023-1729MEDIUM6.5A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an...
CVE-2023-32068MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions pri...
CVE-2023-31145MEDIUM6.1Collabora Online is a collaborative online office suite based on LibreOffice technology. This vulnerability report descr...
CVE-2023-32313MEDIUM5.3vm2 is a sandbox that can run untrusted code with Node's built-in modules. In versions 3.9.17 and lower of vm2 it was po...
CVE-2023-2179MEDIUM6.5The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when up...
CVE-2023-2009MEDIUM4.8Plugin does not sanitize and escape the URL field in the Pretty Url WordPress plugin through 1.5.4 settings, which could...
CVE-2023-23682MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Maintenance Mode plugin <= 1.0...
CVE-2023-1915MEDIUM6.1The Thumbnail carousel slider WordPress plugin before 1.1.10 does not sanitise and escape some parameters before outputt...
CVE-2023-1890MEDIUM6.1The Tablesome WordPress plugin before 1.0.9 does not escape various generated URLs, before outputting them in attributes...
CVE-2023-1839MEDIUM4.8The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.6 does not sanitize and escape some of its sett...
CVE-2023-1835MEDIUM6.1The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it bac...
CVE-2023-1596MEDIUM6.1The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in th...
CVE-2023-1019MEDIUM5.4The Help Desk WP WordPress plugin through 1.2.0 does not sanitise and escape some parameters, which could allow users wi...
CVE-2023-0892MEDIUM4.8The BizLibrary WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-0763MEDIUM4.3The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting H...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now