2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5252MEDIUM5.4The FareHarbor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and i...
CVE-2023-5251MEDIUM5.4The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing ...
CVE-2023-5250HIGH8.8The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a s...
CVE-2023-5199HIGH8.8The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and ...
CVE-2023-5164MEDIUM5.4The Bellows Accordion Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions ...
CVE-2023-5049MEDIUM5.4The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'raf...
CVE-2023-44078Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-41605Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-40943Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-5833HIGH8.8Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.
CVE-2023-5832CRITICAL9.1Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.
CVE-2023-5844HIGH7.2Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.
CVE-2023-42431MEDIUM5.4Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbi...
CVE-2023-45799CRITICAL9.8In MLSoft TCO!stream versions 8.0.22.1115 and below, a vulnerability exists due to insufficient permission validation. T...
CVE-2023-45798CRITICAL9.8In Yettiesoft VestCert versions 2.36 to 2.5.29, a vulnerability exists due to improper validation of third-party modules...
CVE-2023-45797CRITICAL9.8A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotel...
CVE-2023-45746MEDIUM5.4Cross-site scripting vulnerability in Movable Type series allows a remote authenticated attacker to inject an arbitrary ...
CVE-2023-44141HIGH7.8Inkdrop prior to v5.6.0 allows a local attacker to conduct a code injection attack by having a legitimate user open a sp...
CVE-2023-46867MEDIUM6.5In International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a...
CVE-2023-46866MEDIUM6.5In International Color Consortium DemoIccMAX 79ecb74, CIccCLUT::Interp3d in IccProfLib/IccTagLut.cpp in libSampleICC.a a...
CVE-2023-5842MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.
CVE-2023-46865HIGH7.2/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PH...
CVE-2023-4393MEDIUM6.1HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform...
CVE-2023-46864MEDIUM5.3Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/d...
CVE-2023-46863HIGH7.5Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/downl...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now