2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42659HIGH8.8 In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authentic...
CVE-2023-41425MEDIUM6.1Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code...
CVE-2023-3889HIGH7.8A local non-privileged user can make improper GPU memory processing operations. If the operations are carefully prepared...
CVE-2023-36527HIGH8.8Improper Neutralization of Formula Elements in a CSV File vulnerability in BestWebSoft Post to CSV by BestWebSoft.This i...
CVE-2023-25983HIGH8.8Improper Neutralization of Formula Elements in a CSV File vulnerability in WPOmnia KB Support.This issue affects KB Supp...
CVE-2023-23796CRITICAL9.8Improper Neutralization of Formula Elements in a CSV File vulnerability in Muneeb Form Builder | Create Responsive Conta...
CVE-2023-23678HIGH7.2Improper Neutralization of Formula Elements in a CSV File vulnerability in WPEkaClub WP Cookie Consent ( for GDPR, CCPA ...
CVE-2023-22719CRITICAL9.8Improper Neutralization of Formula Elements in a CSV File vulnerability in GiveWP.This issue affects GiveWP: from n/a th...
CVE-2023-47456CRITICAL9.1Tenda AX1806 V1.0.0.1 contains a stack overflow vulnerability in function sub_455D4, called by function fromSetWirelessR...
CVE-2023-47455CRITICAL9.1Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are dire...
CVE-2023-33481CRITICAL9.8RemoteClinic 2.0 is vulnerable to a time-based blind SQL injection attack in the 'start' GET parameter of patients/index...
CVE-2023-33480HIGH8.8RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged ...
CVE-2023-33479CRITICAL9.8RemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file.
CVE-2023-33478CRITICAL9.8RemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php.
CVE-2023-5709MEDIUM6.5The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a...
CVE-2023-5703MEDIUM5.4The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2023-5669MEDIUM5.4The Featured Image Caption plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode ...
CVE-2023-5661MEDIUM5.4The Social Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialfeed' shortcod...
CVE-2023-5660MEDIUM5.4The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s...
CVE-2023-5659MEDIUM5.4The Interact: Embed A Quiz On Your Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2023-5577MEDIUM5.4The Bitly's plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpbitly' shortcode in al...
CVE-2023-5567MEDIUM5.4The QR Code Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'qrcodetag' shortcode in versions ...
CVE-2023-4888MEDIUM5.4The Simple Like Page Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sfp-page-plugin' shor...
CVE-2023-4842MEDIUM5.4The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social...
CVE-2023-0436HIGH7.5The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now