2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34375MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web SEO by 10Web plugin <= 1.2.9 versions.
CVE-2023-32957MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dazzlersoft Team Members Showcase plugin <= 1.3.4 vers...
CVE-2023-32796MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in MingoCommerce WooCommerce Product Enquiry plugin <= 2.3.4 ver...
CVE-2023-28621MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wishfulthemes Rais...
CVE-2023-48134HIGH7.5nagayama_copabowl Line 13.6.1 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor.
CVE-2023-47512MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3...
CVE-2023-47511MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SO WP Pinyin Slugs plugin <= 2.3.0 versions.
CVE-2023-47509MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ioannup Edit WooCommerce Templates plugin <= 1.1.1 version...
CVE-2023-47508MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Averta Master Slider Pro plugin <= 3.6.5 versions.
CVE-2023-47245MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Viewer plugin <= 1.7 versions.
CVE-2023-47242MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7....
CVE-2023-47240MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Codeboxr CBX Map for Google Map & OpenStreetMap ...
CVE-2023-47239MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Paterson Easy PayPal Shopping Cart plugin ...
CVE-2023-6176MEDIUM4.7A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functional...
CVE-2023-48056HIGH7.5PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerabil...
CVE-2023-48055HIGH7.5SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the dis...
CVE-2023-48054HIGH7.4Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host...
CVE-2023-48053HIGH7.5Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerabilit...
CVE-2023-48052HIGH7.4Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and...
CVE-2023-47514MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in lawrenceowen, gcubero, acunnningham, fmahmood Star CloudPR...
CVE-2023-6038HIGH7.5A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to re...
CVE-2023-6022HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository prefecthq/prefect prior to 2.16.5.
CVE-2023-6021HIGH7.5LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed...
CVE-2023-6019CRITICAL9.8A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system r...
CVE-2023-6017HIGH7.1H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now