2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5976MEDIUM4.3Improper Access Control in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-5904MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5903MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5902MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5901MEDIUM4.8Cross-site Scripting in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5900MEDIUM4.3Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5748MEDIUM5.5Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VP...
CVE-2023-41036HIGH7.8Macvim is a text editor for MacOS. Prior to version 178, Macvim makes use of an insecure interprocess communication (IPC...
CVE-2023-40453MEDIUM6.5Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, whi...
CVE-2023-38509MEDIUM4.3XWiki Platform is a generic wiki platform. In org.xwiki.platform:xwiki-platform-livetable-ui starting with version 3.5-m...
CVE-2023-2675CRITICAL9.8Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.
CVE-2023-36409MEDIUM6.5Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2023-36769MEDIUM5.4Microsoft OneNote Spoofing Vulnerability
CVE-2023-47004HIGH8.8Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to exe...
CVE-2023-45556MEDIUM5.4Cross Site Scripting vulnerability in Mybb Mybb Forums v.1.8.33 allows a local attacker to execute arbitrary code via th...
CVE-2023-5771MEDIUM6.1Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can sen...
CVE-2023-5605MEDIUM4.8The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow hi...
CVE-2023-5601CRITICAL9.8The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, all...
CVE-2023-5530MEDIUM4.8The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could a...
CVE-2023-5454HIGH7.5The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, all...
CVE-2023-5355HIGH8.1The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files,...
CVE-2023-5354MEDIUM6.1The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in ...
CVE-2023-5352MEDIUM4.3The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing us...
CVE-2023-5228MEDIUM4.8The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could all...
CVE-2023-5181MEDIUM4.8The WP Discord Invite WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now