2023 CVE Vulnerabilities
31,249 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1624 | MEDIUM | 6.5 | 0.3% | Apr 24, 2023 | The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be de... |
| CVE-2023-1623 | MEDIUM | 6.5 | 0.4% | Apr 24, 2023 | The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug informati... |
| CVE-2023-1435 | MEDIUM | 6.1 | 0.5% | Apr 24, 2023 | The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting the... |
| CVE-2023-1420 | MEDIUM | 6.1 | 0.5% | Apr 24, 2023 | The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise an... |
| CVE-2023-1414 | MEDIUM | 4.3 | 0.2% | Apr 24, 2023 | The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in part... |
| CVE-2023-1324 | MEDIUM | 6.1 | 0.6% | Apr 24, 2023 | The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputtin... |
| CVE-2023-1129 | MEDIUM | 6.5 | 0.6% | Apr 24, 2023 | The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making... |
| CVE-2023-1126 | MEDIUM | 5.4 | 0.4% | Apr 24, 2023 | The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any au... |
| CVE-2023-0899 | MEDIUM | 6.1 | 0.5% | Apr 24, 2023 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputt... |
| CVE-2023-0424 | MEDIUM | 5.4 | 0.4% | Apr 24, 2023 | The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authentica... |
| CVE-2023-0420 | MEDIUM | 4.8 | 0.2% | Apr 24, 2023 | The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising... |
| CVE-2023-0418 | MEDIUM | 5.4 | 0.4% | Apr 24, 2023 | The Video Central for WordPress plugin through 1.3.0 does not validate and escape some of its shortcode attributes befor... |
| CVE-2023-0276 | MEDIUM | 5.4 | 0.5% | Apr 24, 2023 | The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attribu... |
| CVE-2023-27990 | MEDIUM | 4.8 | 0.3% | Apr 24, 2023 | The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series fi... |
| CVE-2023-26097 | MEDIUM | 5.5 | 0.2% | Apr 24, 2023 | An issue was discovered in Telindus Apsal 3.14.2022.235 b. Unauthorized actions that could modify the application behavi... |
| CVE-2023-26059 | MEDIUM | 5.4 | 0.4% | Apr 24, 2023 | An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP... |
| CVE-2023-22918 | MEDIUM | 6.5 | 0.8% | Apr 24, 2023 | A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 t... |
| CVE-2023-30544 | MEDIUM | 4.3 | 0.4% | Apr 24, 2023 | Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update th... |
| CVE-2023-26494 | MEDIUM | 6.1 | 0.6% | Apr 24, 2023 | lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login pa... |
| CVE-2023-26061 | MEDIUM | 5.4 | 0.4% | Apr 24, 2023 | An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard ... |
| CVE-2023-30776 | MEDIUM | 6.5 | 2.1% | Apr 24, 2023 | An authenticated user with specific data permissions could access database connections stored passwords by requesting a ... |
| CVE-2023-29848 | MEDIUM | 4.8 | 1.9% | Apr 24, 2023 | Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in... |
| CVE-2023-29479 | MEDIUM | 5.3 | 0.9% | Apr 24, 2023 | Ribose RNP before 0.16.3 may hang when the input is malformed. |
| CVE-2023-29570 | MEDIUM | 5.5 | 0.3% | Apr 24, 2023 | Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerabil... |
| CVE-2023-23892 | MEDIUM | 5.4 | 0.4% | Apr 24, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jamie Poitra M Chart plugin <= 1.9.4 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now