2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-27929MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4...
CVE-2023-23542MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura...
CVE-2023-23538MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. An a...
CVE-2023-23537MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura...
CVE-2023-23535MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16...
CVE-2023-23534MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5. Processin...
CVE-2023-23533MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. An a...
CVE-2023-23528MEDIUM6.5An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 16.4, iOS 16.4 and iPadOS...
CVE-2023-23527MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS...
CVE-2023-23494MEDIUM5.3A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. A user i...
CVE-2023-30860MEDIUM5.4WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule...
CVE-2023-1979MEDIUM6.5The Web Stories for WordPress plugin supports the WordPress built-in functionality of protecting content with a password...
CVE-2023-30019MEDIUM5.3imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL para...
CVE-2023-28493MEDIUM5.4Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes NewsMag theme <= 2.4.4 versions.
CVE-2023-24408MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart pl...
CVE-2023-22791MEDIUM4.8A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a spec...
CVE-2023-1905MEDIUM5.4The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page short...
CVE-2023-1806MEDIUM6.1The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outp...
CVE-2023-1660MEDIUM6.1The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing...
CVE-2023-1651MEDIUM5.4The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in the AJAX action responsible to upda...
CVE-2023-1649MEDIUM4.8The AI ChatBot WordPress plugin before 4.5.1 does not sanitise and escape numerous of its settings, which could allow hi...
CVE-2023-1011MEDIUM6.1The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the das...
CVE-2023-0948MEDIUM6.1The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in att...
CVE-2023-0894MEDIUM4.8The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settin...
CVE-2023-0544MEDIUM4.8The WP Login Box WordPress plugin through 2.0.2 does not sanitise and escape some of its settings, which could allow hig...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now