2023 CVE Vulnerabilities

31,401 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4388MEDIUM4.8The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privil...
CVE-2023-4290MEDIUM6.1The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting i...
CVE-2023-4289MEDIUM5.4The WP Matterport Shortcode WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes ...
CVE-2023-45150MEDIUM4.3Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server wa...
CVE-2023-45149MEDIUM4.3Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection of public...
CVE-2023-43121HIGH7.5A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32....
CVE-2023-43119CRITICAL9.8An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 ...
CVE-2023-43118HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32...
CVE-2023-3746MEDIUM5.4The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allo...
CVE-2023-3707MEDIUM4.3The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong t...
CVE-2023-3706MEDIUM4.3The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to ...
CVE-2023-3279MEDIUM4.9The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to g...
CVE-2023-3155HIGH7.2The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack ...
CVE-2023-3154HIGH7.5The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input p...
CVE-2023-29484MEDIUM6.5In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password.
CVE-2023-45683MEDIUM6.1github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the AC...
CVE-2023-45669MEDIUM5.3WebAuthn4J Spring Security provides Web Authentication specification support for Spring applications. Affected versions ...
CVE-2023-45660MEDIUM4.3Nextcloud mail is an email app for the Nextcloud home server platform. In affected versions a missing check of origin, t...
CVE-2023-45151HIGH8.8Nextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext...
CVE-2023-45148MEDIUM4.3Nextcloud is an open source home cloud server. When Memcached is used as `memcache.distributed` the rate limiting in Nex...
CVE-2023-43120HIGH8.8An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attac...
CVE-2023-40180HIGH7.5 silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a re...
CVE-2023-45985HIGH7.5TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack ove...
CVE-2023-45984CRITICAL9.8TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack over...
CVE-2023-45690MEDIUM4.9Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user that's aut...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now