2023 CVE Vulnerabilities

31,399 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-46090MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions.
CVE-2023-41096MEDIUM6.1Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High module...
CVE-2023-41095CRITICAL9.1Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High module...
CVE-2023-5781CRITICAL9.8A vulnerability, which was classified as critical, has been found in Tongda OA 2017 11.10. This issue affects the functi...
CVE-2023-5780CRITICAL9.8A vulnerability classified as critical was found in Tongda OA 2017 11.10. This vulnerability affects unknown code of the...
CVE-2023-46094MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track Google Analytics 4, Facebook Pixel & Conv...
CVE-2023-46088MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology WP Full Stripe Free plugin <= 1.6.1 versi...
CVE-2023-46081MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions.
CVE-2023-46077MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plugin <= 2.2...
CVE-2023-46076MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao WooCommerce PDF Invoice Builder, Create invoices, p...
CVE-2023-46075MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Contact Form Builder, Contact Widget plugin <= 2....
CVE-2023-32116MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in TotalPress.Org Custom post types, Custom Fields & more...
CVE-2023-5802HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Mihai Iova WordPress Knowledge base & Documentation Plugin – WP Knowl...
CVE-2023-46074MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Borbis Media FreshMail For WordPress plugin <= 2.3.2 versi...
CVE-2023-46072MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin ...
CVE-2023-30492MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vark Minimum Purchase for WooCommerce plugin <= ...
CVE-2023-5798HIGH8.8The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_ge...
CVE-2023-5139HIGH7.8Potential buffer overflow vulnerability at the following location in the Zephyr STM32 Crypto driver
CVE-2023-46754MEDIUM5.3The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary num...
CVE-2023-46753MEDIUM5.9An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without manda...
CVE-2023-46752MEDIUM5.9An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
CVE-2023-31421HIGH7.5It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whe...
CVE-2023-31422HIGH7.5An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. Th...
CVE-2023-46667HIGH8.1An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into th...
CVE-2023-46668CRITICAL9.1If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitl...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now