2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-47379MEDIUM5.4Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload func...
CVE-2023-46643MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GARY JEZORSKI CloudNet360 plugin <= 3.2.0 versions.
CVE-2023-46642MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in sahumedia SAHU TikTok Pixel for E-Commerce plugin <= 1...
CVE-2023-5759HIGH7.5In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified....
CVE-2023-5136MEDIUM5.5An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An atta...
CVE-2023-47397CRITICAL9.8WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
CVE-2023-47107HIGH8.8PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component ...
CVE-2023-46640MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in D. Relton Medialist plugin <= 1.3.9 versions.
CVE-2023-46627MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 v...
CVE-2023-46626MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FLOWFACT WP Connector plugin <= 2.1.7 versions.
CVE-2023-46621MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin...
CVE-2023-46613MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jens Kuerschner Add to Calendar Button plugin <=...
CVE-2023-45849CRITICAL9.8An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2....
CVE-2023-45319HIGH7.5In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was id...
CVE-2023-45140MEDIUM4.6The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. SCP and SFTP plugins...
CVE-2023-35767HIGH7.5In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was ...
CVE-2023-32298MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kathy Darling Simple User Listing plugin <= 1.9.2 versions...
CVE-2023-6012CRITICAL9.8An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vu...
CVE-2023-46759HIGH7.5Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service co...
CVE-2023-46758HIGH7.5Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerabilit...
CVE-2023-46757HIGH7.5The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of...
CVE-2023-46756MEDIUM5.3Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may caus...
CVE-2023-46774HIGH7.5Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC ava...
CVE-2023-46772HIGH7.5Vulnerability of parameters being out of the value range in the QMI service module. Successful exploitation of this vuln...
CVE-2023-46767HIGH7.5Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause p...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now