2023 CVE Vulnerabilities

31,401 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45064MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <...
CVE-2023-45062MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Thomas Scholl canvasio3D Light plugin <= 2.4.6 versions.
CVE-2023-45059MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Gumroad plugin <= 3.1.0 versions.
CVE-2023-45057MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hitsteps Web Analytics plugin <= 5.86 versions.
CVE-2023-45056MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in 100plugins Open User Map plugin <= 1.3.26 versions.
CVE-2023-45054MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions.
CVE-2023-45051MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Image vertical reel scroll slideshow plu...
CVE-2023-5621MEDIUM4.8The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title...
CVE-2023-4938MEDIUM4.3The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ...
CVE-2023-45049MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <...
CVE-2023-45008MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPJohnny Comment Reply Email plugin <= 1.0.3 versions.
CVE-2023-25476MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ezoic AmpedSense – AdSense Split Tester plugin <= 4.68 ver...
CVE-2023-42319HIGH7.5Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of servi...
CVE-2023-5538MEDIUM6.1The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in vers...
CVE-2023-3254MEDIUM4.3The Widgets for Google Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i...
CVE-2023-39332CRITICAL9.8Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, t...
CVE-2023-39331HIGH7.5A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path travers...
CVE-2023-38552HIGH7.5When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can inter...
CVE-2023-38546LOW3.7This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of c...
CVE-2023-38545CRITICAL9.8This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the h...
CVE-2023-35084CRITICAL9.8Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 ...
CVE-2023-35083MEDIUM6.5Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on ...
CVE-2023-5626HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16.
CVE-2023-5552HIGH7.5A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to ...
CVE-2023-45811HIGH7.8Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now