2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48051HIGH7.5An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption pad...
CVE-2023-48192HIGH7.8An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracero...
CVE-2023-48176CRITICAL9.8An Insecure Permissions issue in WebsiteGuide v.0.2 allows a remote attacker to gain escalated privileges via crafted jw...
CVE-2023-6178MEDIUM6.5 An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing applicatio...
CVE-2023-6062MEDIUM6.5 An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on t...
CVE-2023-47311MEDIUM6.1An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.
CVE-2023-47172HIGH7.8Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15, WithSecure Ser...
CVE-2023-46471MEDIUM5.4Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbi...
CVE-2023-46470MEDIUM5.4Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbi...
CVE-2023-48111HIGH7.5Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentContro...
CVE-2023-48110HIGH7.5Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControl...
CVE-2023-48109HIGH7.5Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the function saveParentCon...
CVE-2023-47417MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the component /shells/embedder.html of DZSlides after v2011.07.25 allows att...
CVE-2023-46990CRITICAL9.8Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a c...
CVE-2023-38823CRITICAL9.8Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to exec...
CVE-2023-5799MEDIUM5.4The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing ...
CVE-2023-5652CRITICAL9.8The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not esca...
CVE-2023-5651MEDIUM5.4The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensu...
CVE-2023-5640CRITICAL9.8The Article Analytics WordPress plugin does not properly sanitise and escape a parameter before using it in a SQL statem...
CVE-2023-5610MEDIUM5.4The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user ...
CVE-2023-5609MEDIUM6.1The Seraphinite Accelerator WordPress plugin before 2.2.29 does not sanitise and escape a parameter before outputting it...
CVE-2023-5509MEDIUM5.4The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in use...
CVE-2023-5343MEDIUM4.8The Popup box WordPress plugin before 3.7.9 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-5340CRITICAL9.8The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX actio...
CVE-2023-5140MEDIUM6.1The Bonus for Woo WordPress plugin before 5.8.3 does not sanitise and escape some parameters before outputting them back...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now