2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-23553MEDIUM6.1 Control By Web X-400 devices are vulnerable to a cross-site scripting attack, which could result in private and session...
CVE-2023-25159MEDIUM5.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is...
CVE-2023-24804MEDIUM4.4The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the a...
CVE-2023-23948MEDIUM5.5The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCl...
CVE-2023-0810MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.11.
CVE-2023-0405MEDIUM4.3The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin...
CVE-2023-0379MEDIUM5.4The Spotlight Social Feeds WordPress plugin before 1.4.3 does not validate and escape some of its block options before o...
CVE-2023-0373MEDIUM5.4The Lightweight Accordion WordPress plugin before 1.5.15 does not validate and escape some of its block options before o...
CVE-2023-0362MEDIUM5.4Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes befor...
CVE-2023-0360MEDIUM5.4The Location Weather WordPress plugin before 1.3.4 does not validate and escape some of its block options before outputt...
CVE-2023-0333MEDIUM5.4The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using ...
CVE-2023-0275MEDIUM5.4The Easy Accept Payments for PayPal WordPress plugin before 4.9.10 does not validate and escape some of its shortcode at...
CVE-2023-0270MEDIUM5.4The YaMaps for WordPress Plugin WordPress plugin before 0.6.26 does not validate and escape some of its shortcode attrib...
CVE-2023-0177MEDIUM5.4The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortco...
CVE-2023-0169MEDIUM5.4The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before output...
CVE-2023-0166MEDIUM5.4The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of i...
CVE-2023-0151MEDIUM5.4The uTubeVideo Gallery WordPress plugin before 2.0.8 does not validate and escape some of its shortcode attributes befor...
CVE-2023-0099MEDIUM6.1The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in ...
CVE-2023-0075MEDIUM5.4The Amazon JS WordPress plugin through 0.10 does not validate and escape some of its shortcode attributes before outputt...
CVE-2023-0061MEDIUM5.4The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its sho...
CVE-2023-0060MEDIUM5.4The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes ...
CVE-2023-0034MEDIUM5.4The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attribute...
CVE-2023-0808MEDIUM6.8A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as pr...
CVE-2023-25727MEDIUM5.4In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file...
CVE-2023-22367MEDIUM5.9Ichiran App for iOS versions prior to 3.1.0 and Ichiran App for Android versions prior to 3.1.0 improperly verify server...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now