2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-1624MEDIUM6.5The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be de...
CVE-2023-1623MEDIUM6.5The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug informati...
CVE-2023-1435MEDIUM6.1The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting the...
CVE-2023-1420MEDIUM6.1The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise an...
CVE-2023-1414MEDIUM4.3The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in part...
CVE-2023-1324MEDIUM6.1The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputtin...
CVE-2023-1129MEDIUM6.5The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making...
CVE-2023-1126MEDIUM5.4The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any au...
CVE-2023-0899MEDIUM6.1The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputt...
CVE-2023-0424MEDIUM5.4The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authentica...
CVE-2023-0420MEDIUM4.8The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising...
CVE-2023-0418MEDIUM5.4The Video Central for WordPress plugin through 1.3.0 does not validate and escape some of its shortcode attributes befor...
CVE-2023-0276MEDIUM5.4The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attribu...
CVE-2023-27990MEDIUM4.8The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series fi...
CVE-2023-26097MEDIUM5.5An issue was discovered in Telindus Apsal 3.14.2022.235 b. Unauthorized actions that could modify the application behavi...
CVE-2023-26059MEDIUM5.4An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP...
CVE-2023-22918MEDIUM6.5A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 t...
CVE-2023-30544MEDIUM4.3Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update th...
CVE-2023-26494MEDIUM6.1lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login pa...
CVE-2023-26061MEDIUM5.4An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard ...
CVE-2023-30776MEDIUM6.5An authenticated user with specific data permissions could access database connections stored passwords by requesting a ...
CVE-2023-29848MEDIUM4.8Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in...
CVE-2023-29479MEDIUM5.3Ribose RNP before 0.16.3 may hang when the input is malformed.
CVE-2023-29570MEDIUM5.5Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerabil...
CVE-2023-23892MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jamie Poitra M Chart plugin <= 1.9.4 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now