2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5119MEDIUM4.8The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission s...
CVE-2023-4970MEDIUM4.8The PubyDoc WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2023-4824HIGH8.8The WooHoo Newspaper Magazine theme does not have CSRF check in place when updating its settings, which could allow atta...
CVE-2023-4808MEDIUM4.8The WP Post Popup WordPress plugin through 3.7.3 does not sanitise and escape some of its inputs, which could allow high...
CVE-2023-4799MEDIUM5.4The Magic Embeds WordPress plugin before 3.1.2 does not validate and escape some of its shortcode attributes before outp...
CVE-2023-48309MEDIUM5.3NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the defau...
CVE-2023-48300MEDIUM5.4The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored ...
CVE-2023-48293HIGH8.8The XWiki Admin Tools Application provides tools to help the administration of XWiki. Prior to version 4.5.1, a cross-si...
CVE-2023-38885HIGH8.8OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole ap...
CVE-2023-38884HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows ...
CVE-2023-38883MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic all...
CVE-2023-38882MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic all...
CVE-2023-38881MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic all...
CVE-2023-38880CRITICAL9.8The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database b...
CVE-2023-38879HIGH7.5The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a direc...
CVE-2023-48292HIGH8.8The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior ...
CVE-2023-48241HIGH7.5XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, a...
CVE-2023-48240HIGH8.8XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents a...
CVE-2023-48223MEDIUM5.9fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to version 3.3.2, the fast-jwt library does not proper...
CVE-2023-48221HIGH8.8wire-avs provides Audio, Visual, and Signaling (AVS) functionality sure the secure messaging software Wire. Prior to ver...
CVE-2023-48218MEDIUM5.3The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3....
CVE-2023-35762CRITICAL9.8 Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could...
CVE-2023-29155CRITICAL9.8Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system ...
CVE-2023-36013MEDIUM6.5PowerShell Information Disclosure Vulnerability
CVE-2023-6197MEDIUM5.4The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now