2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5357MEDIUM5.4The Instagram for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions...
CVE-2023-5291MEDIUM5.4The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in vers...
CVE-2023-3213MEDIUM5.3The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2023-37404CRITICAL9.8IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code ...
CVE-2023-35905MEDIUM5.4IBM FileNet Content Manager 5.5.8, 5.5.10, and 5.5.11 is vulnerable to cross-site scripting. This vulnerability allows u...
CVE-2023-39647CRITICAL9.8Improper neutralization of SQL parameter in Theme Volty CMS Category Product module for PrestaShop. In the module “Theme...
CVE-2023-39651CRITICAL9.8Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module “Theme Volty C...
CVE-2023-39649CRITICAL9.8Improper neutralization of SQL parameter in Theme Volty CMS Category Slider module for PrestaShop. In the module “Theme ...
CVE-2023-39648CRITICAL9.8Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volt...
CVE-2023-39646CRITICAL9.8Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “...
CVE-2023-44974CRITICAL9.8An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execut...
CVE-2023-44973CRITICAL9.8An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to exec...
CVE-2023-43953MEDIUM5.4SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.
CVE-2023-43952MEDIUM5.4SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management comp...
CVE-2023-43951MEDIUM5.4SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component.
CVE-2023-43898MEDIUM5.5Nothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulne...
CVE-2023-43176HIGH8.8A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplyi...
CVE-2023-40519MEDIUM6.1A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized...
CVE-2023-39645CRITICAL9.8Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Vol...
CVE-2023-33273CRITICAL9.8An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS c...
CVE-2023-33272CRITICAL9.8An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS co...
CVE-2023-33271CRITICAL9.8An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is...
CVE-2023-33270CRITICAL9.8An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS c...
CVE-2023-33269CRITICAL9.8An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to ...
CVE-2023-33268CRITICAL9.8An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulner...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now