2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0492MEDIUM5.4The GS Products Slider for WooCommerce WordPress plugin before 1.5.9 does not validate and escape some of its shortcode ...
CVE-2023-0453MEDIUM4.3The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensu...
CVE-2023-0442MEDIUM6.1The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outpu...
CVE-2023-0429MEDIUM4.8The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape some of its settings, which could allow high ...
CVE-2023-0428MEDIUM6.1The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2023-0419MEDIUM5.4The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attribut...
CVE-2023-0380MEDIUM5.4The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before...
CVE-2023-0378MEDIUM5.4The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them...
CVE-2023-0375MEDIUM5.4The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before out...
CVE-2023-0372MEDIUM5.4The EmbedStories WordPress plugin before 0.7.5 does not validate and escape some of its shortcode attributes before outp...
CVE-2023-0371MEDIUM5.4The EmbedSocial WordPress plugin before 1.1.28 does not validate and escape some of its shortcode attributes before outp...
CVE-2023-0366MEDIUM5.4The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before o...
CVE-2023-0285MEDIUM5.4The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which coul...
CVE-2023-0271MEDIUM5.4The WP Font Awesome WordPress plugin before 1.7.9 does not validate and escape some of its shortcode attributes before o...
CVE-2023-0231MEDIUM5.4The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting th...
CVE-2023-0067MEDIUM5.4The Timed Content WordPress plugin before 2.73 does not validate and escape some of its shortcode attributes before outp...
CVE-2023-0059MEDIUM5.4The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputtin...
CVE-2023-26265MEDIUM5.3The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL...
CVE-2023-26235MEDIUM6.1JD-GUI 1.6.6 allows XSS via util/net/InterProcessCommunicationUtil.java.
CVE-2023-25569MEDIUM5.7Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page...
CVE-2023-0914MEDIUM5.3Improper Authorization in GitHub repository pixelfed/pixelfed prior to 0.11.4.
CVE-2023-0909MEDIUM5.5A vulnerability, which was classified as problematic, was found in cxasm notepad-- 1.22. This affects an unknown part of...
CVE-2023-0907MEDIUM5.5A vulnerability, which was classified as problematic, has been found in Filseclab Twister Antivirus 8.17. Affected by th...
CVE-2023-0902MEDIUM5.4A vulnerability was found in SourceCodester Simple Food Ordering System 1.0. It has been classified as problematic. This...
CVE-2023-0901MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed prior to 0.11.4.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now