2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0492 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The GS Products Slider for WooCommerce WordPress plugin before 1.5.9 does not validate and escape some of its shortcode ... |
| CVE-2023-0453 | MEDIUM | 4.3 | 0.6% | Feb 21, 2023 | The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensu... |
| CVE-2023-0442 | MEDIUM | 6.1 | 0.5% | Feb 21, 2023 | The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outpu... |
| CVE-2023-0429 | MEDIUM | 4.8 | 0.5% | Feb 21, 2023 | The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2023-0428 | MEDIUM | 6.1 | 0.6% | Feb 21, 2023 | The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape a parameter before outputting it back in the ... |
| CVE-2023-0419 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attribut... |
| CVE-2023-0380 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before... |
| CVE-2023-0378 | MEDIUM | 5.4 | 0.6% | Feb 21, 2023 | The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them... |
| CVE-2023-0375 | MEDIUM | 5.4 | 0.7% | Feb 21, 2023 | The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before out... |
| CVE-2023-0372 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The EmbedStories WordPress plugin before 0.7.5 does not validate and escape some of its shortcode attributes before outp... |
| CVE-2023-0371 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The EmbedSocial WordPress plugin before 1.1.28 does not validate and escape some of its shortcode attributes before outp... |
| CVE-2023-0366 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before o... |
| CVE-2023-0285 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which coul... |
| CVE-2023-0271 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The WP Font Awesome WordPress plugin before 1.7.9 does not validate and escape some of its shortcode attributes before o... |
| CVE-2023-0231 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting th... |
| CVE-2023-0067 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Timed Content WordPress plugin before 2.73 does not validate and escape some of its shortcode attributes before outp... |
| CVE-2023-0059 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputtin... |
| CVE-2023-26265 | MEDIUM | 5.3 | 0.6% | Feb 21, 2023 | The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL... |
| CVE-2023-26235 | MEDIUM | 6.1 | 0.4% | Feb 21, 2023 | JD-GUI 1.6.6 allows XSS via util/net/InterProcessCommunicationUtil.java. |
| CVE-2023-25569 | MEDIUM | 5.7 | 0.4% | Feb 20, 2023 | Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page... |
| CVE-2023-0914 | MEDIUM | 5.3 | 0.5% | Feb 19, 2023 | Improper Authorization in GitHub repository pixelfed/pixelfed prior to 0.11.4. |
| CVE-2023-0909 | MEDIUM | 5.5 | 0.3% | Feb 18, 2023 | A vulnerability, which was classified as problematic, was found in cxasm notepad-- 1.22. This affects an unknown part of... |
| CVE-2023-0907 | MEDIUM | 5.5 | 0.2% | Feb 18, 2023 | A vulnerability, which was classified as problematic, has been found in Filseclab Twister Antivirus 8.17. Affected by th... |
| CVE-2023-0902 | MEDIUM | 5.4 | 2.7% | Feb 18, 2023 | A vulnerability was found in SourceCodester Simple Food Ordering System 1.0. It has been classified as problematic. This... |
| CVE-2023-0901 | MEDIUM | 5.3 | 0.6% | Feb 18, 2023 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed prior to 0.11.4. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now