2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-1121MEDIUM4.8The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow...
CVE-2023-1120MEDIUM4.8The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow...
CVE-2023-0983MEDIUM6.1The stylish-cost-calculator-premium WordPress plugin before 7.9.0 does not sanitise and escape a parameter before output...
CVE-2023-0893MEDIUM4.8The Time Sheets WordPress plugin before 1.29.3 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-0874MEDIUM4.8The Klaviyo WordPress plugin before 3.0.10 does not sanitize and escape some of its settings, which could allow high-pri...
CVE-2023-0605MEDIUM4.8The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which c...
CVE-2023-0546MEDIUM5.4The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in ifr...
CVE-2023-0423MEDIUM4.8The WordPress Amazon S3 Plugin WordPress plugin before 1.6 does not sanitise and escape a parameter before outputting it...
CVE-2023-0422MEDIUM4.8The Article Directory WordPress plugin through 1.3 does not properly sanitize the `publish_terms_text` setting before di...
CVE-2023-0363MEDIUM5.4The Scheduled Announcements Widget WordPress plugin before 1.0 does not validate and escape some of its shortcode attrib...
CVE-2023-0157MEDIUM4.8The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting ...
CVE-2023-0156MEDIUM4.9The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings p...
CVE-2023-26788MEDIUM6.1Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause t...
CVE-2023-26120MEDIUM6.1This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-j...
CVE-2023-30456MEDIUM6.5An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency ...
CVE-2023-30450MEDIUM4.3rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which...
CVE-2023-1961MEDIUM6.1A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been classified as problematic....
CVE-2023-1948MEDIUM6.1A vulnerability, which was classified as problematic, has been found in PHPGurukul BP Monitoring Management System 1.0. ...
CVE-2023-24626MEDIUM6.5socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and F...
CVE-2023-1946MEDIUM6.1A vulnerability was found in SourceCodester Survey Application System 1.0 and classified as problematic. This issue affe...
CVE-2023-1801MEDIUM6.5The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network pa...
CVE-2023-23762MEDIUM5.3An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displa...
CVE-2023-23761MEDIUM5.3An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor t...
CVE-2023-1909MEDIUM6.5A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected...
CVE-2023-29388MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in impleCode Product Catalog Simple plugin <= 1.6.17 versions...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now