2023 CVE Vulnerabilities

31,400 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5687HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository mosparo/mosparo prior to 1.0.3.
CVE-2023-5686HIGH8.8Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
CVE-2023-23373HIGH8.8An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow ...
CVE-2023-3965MEDIUM6.1The nsc theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, a...
CVE-2023-3962MEDIUM6.1The Winters theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up t...
CVE-2023-3933MEDIUM6.1The Your Journey theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions...
CVE-2023-3487HIGH7.8An integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when readi...
CVE-2023-46287MEDIUM6.1XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php.
CVE-2023-5618MEDIUM5.4The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ver...
CVE-2023-44483MEDIUM6.5All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, a...
CVE-2023-44256MEDIUM6.5A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2...
CVE-2023-34045HIGH7.8VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation f...
CVE-2023-34046HIGH7VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during instal...
CVE-2023-34044MEDIUM6VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that...
CVE-2023-5656Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5533. Reason: This record is a reservatio...
CVE-2023-5615MEDIUM5.4The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-statu...
CVE-2023-5602HIGH8.8The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2023-5534MEDIUM5.4The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 ...
CVE-2023-5533CRITICAL9.8The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks o...
CVE-2023-5337MEDIUM5.4The Contact form Form For All plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortco...
CVE-2023-5292MEDIUM5.4The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acfe_for...
CVE-2023-5231MEDIUM5.4The Magic Action Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to,...
CVE-2023-5121MEDIUM4.8The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set...
CVE-2023-5109MEDIUM5.4The WP Mailto Links – Protect Email Addresses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wpm...
CVE-2023-5086MEDIUM5.4The Copy Anything to Clipboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'copy' shortcode in...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now