2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0762MEDIUM4.3The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting d...
CVE-2023-0761MEDIUM4.3The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting S...
CVE-2023-0644MEDIUM6.1The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various p...
CVE-2023-0520MEDIUM5.4The RapidExpCart WordPress plugin through 1.0 does not sanitize and escape the url parameter in the rapidexpcart endpoin...
CVE-2023-0490MEDIUM5.4The f(x) TOC WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputt...
CVE-2023-0233MEDIUM5.4The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputti...
CVE-2023-23688MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions.
CVE-2023-23683MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ozan Canakli White Label Branding for Elementor Page B...
CVE-2023-23674MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in RVOLA WP Original Media Path plugin <= 2.4.0 versions.
CVE-2023-23654MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SparkPost plugin <= 3.2.5 versions.
CVE-2023-22717MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in nCrafts FormCraft plugin <= 1.2.6 versions.
CVE-2023-22706MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions.
CVE-2023-23449MEDIUM5.3Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 112011...
CVE-2023-23448MEDIUM5.3Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 110021...
CVE-2023-22703MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webcodin WCP Contact Form plugin <= 3.1.0 versions.
CVE-2023-22690MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.775 versions.
CVE-2023-22684MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Subscribers.Com Subscribers plugin <= 1.5.3 versions.
CVE-2023-2692MEDIUM6.1A vulnerability has been found in SourceCodester ICT Laboratory Management System 1.0 and classified as problematic. Aff...
CVE-2023-2691MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Personnel Property Equipment System 1....
CVE-2023-32303MEDIUM5.5Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information...
CVE-2023-2181MEDIUM6.5An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before ...
CVE-2023-2088MEDIUM6.5A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally...
CVE-2023-20880MEDIUM6.7VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to th...
CVE-2023-20879MEDIUM6.7VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privil...
CVE-2023-27863MEDIUM4.9IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB cred...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now