2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5082HIGH7.2The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using ...
CVE-2023-4930MEDIUM6.5The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores a...
CVE-2023-4858MEDIUM4.8The Simple Table Manager WordPress plugin through 1.5.6 does not sanitise and escape some of its settings, which could a...
CVE-2023-4810MEDIUM4.8The Responsive Pricing Table WordPress plugin before 5.1.8 does not sanitise and escape some of its settings, which coul...
CVE-2023-5777CRITICAL9.8 Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the cra...
CVE-2023-5719CRITICAL9.8 The Crimson 3.2 Windows-based configuration tool allows users with administrative access to define new passwords for us...
CVE-2023-46732MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulner...
CVE-2023-46731CRITICAL9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't p...
CVE-2023-46254MEDIUM4.3capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used...
CVE-2023-39345HIGH7.5strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked...
CVE-2023-4700MEDIUM6.5An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 1...
CVE-2023-46728HIGH7.5Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid ...
CVE-2023-46251MEDIUM6.1 MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape...
CVE-2023-45827CRITICAL9.8Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions t...
CVE-2023-44398HIGH8.8Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada...
CVE-2023-4535LOW3.8An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key enc...
CVE-2023-40661MEDIUM6.4Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process u...
CVE-2023-40660MEDIUM6.6A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process...
CVE-2023-5969MEDIUM5.3Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially...
CVE-2023-5968MEDIUM4.9Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being i...
CVE-2023-5967MEDIUM4.3Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a Use...
CVE-2023-5678MEDIUM5.3Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be...
CVE-2023-41378HIGH7.5In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.1...
CVE-2023-5950MEDIUM6.1Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerabi...
CVE-2023-5964HIGH7.2The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exch...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now