2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5975MEDIUM4.3The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6...
CVE-2023-5743MEDIUM5.4The Telephone Number Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'telnumli...
CVE-2023-5658MEDIUM5.4The WP MapIt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_mapit' shortcode in ...
CVE-2023-5532MEDIUM4.3The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6...
CVE-2023-5507MEDIUM5.4The ImageMapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'imagemap' shortcode in versions u...
CVE-2023-5506MEDIUM4.3The ImageMapper plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the...
CVE-2023-46819MEDIUM5.3Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache ...
CVE-2023-47510MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPSolutions-HQ WPDBSpringClean plugin <= 1.6 versions.
CVE-2023-46851MEDIUM4.9Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrato...
CVE-2023-5076MEDIUM5.4The Ziteboard Online Whiteboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ziteboard' sh...
CVE-2023-46845HIGH7.2EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an...
CVE-2023-43886HIGH7.1A buffer overflow in the HTTP server component of Tenda RX9 Pro v22.03.02.20 might allow an authenticated attacker to ov...
CVE-2023-43885HIGH8.1Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attacker...
CVE-2023-42555MEDIUM5.5Use of implicit intent for sensitive communication vulnerability in EasySetup prior to version 11.1.13 allows attackers ...
CVE-2023-42554MEDIUM6.8Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass auth...
CVE-2023-42553MEDIUM5.3Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sa...
CVE-2023-42552LOW3.3Implicit intent hijacking vulnerability in Firewall application prior to versions 12.1.00.24 in Android 11, 13.1.00.16 i...
CVE-2023-42551MEDIUM6.5Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version...
CVE-2023-42550MEDIUM6.5Use of implicit intent for sensitive communication vulnerability in startSignIn in Samsung Account prior to version 14.5...
CVE-2023-42549MEDIUM6.5Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior...
CVE-2023-42548MEDIUM6.5Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account prior...
CVE-2023-42547MEDIUM6.5Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prio...
CVE-2023-42546MEDIUM6.5Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account pr...
CVE-2023-42545HIGH7.5Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13...
CVE-2023-42544MEDIUM5.5Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now