2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-35664MEDIUM5.5In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. Th...
CVE-2023-35658HIGH8.8In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible privilege escalation due to a use after free. This cou...
CVE-2023-4318MEDIUM4.3The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers t...
CVE-2023-4314HIGH7.2The wpDataTables WordPress plugin before 2.1.66 does not validate the "Serialized PHP array" input data before deseriali...
CVE-2023-4307MEDIUM4.3The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, ...
CVE-2023-4294MEDIUM6.1The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing a...
CVE-2023-4278HIGH7.5The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registra...
CVE-2023-4270MEDIUM6.1The Min Max Control WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting it back in th...
CVE-2023-4060MEDIUM4.8The WP Adminify WordPress plugin before 3.1.6 does not sanitise and escape some of its settings, which could allow high ...
CVE-2023-4022MEDIUM4.8The Herd Effects WordPress plugin before 5.2.3 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-41336MEDIUM6.5ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could s...
CVE-2023-40946CRITICAL9.8Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php.
CVE-2023-40945CRITICAL9.8Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails...
CVE-2023-40944CRITICAL9.8Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php.
CVE-2023-40150CRITICAL9.8 Softneta MedDream PACS does not perform an authentication check and performs some dangerous functionality, which could ...
CVE-2023-3510MEDIUM5.4The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and i...
CVE-2023-3170MEDIUM4.8The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, do...
CVE-2023-3169MEDIUM6.1The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, do...
CVE-2023-39227HIGH7.5​Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers ...
CVE-2023-38256HIGH7.5Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3....
CVE-2023-36497HIGH8.8Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3....
CVE-2023-2705MEDIUM6.1The gAppointments WordPress plugin before 1.10.0 does not sanitise and escape a parameter before outputting it back in t...
CVE-2023-41256CRITICAL9.1 Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3...
CVE-2023-41103MEDIUM5.4Interact 7.9.79.5 allows stored Cross-site Scripting (XSS) attacks in several locations, allowing an attacker to store a...
CVE-2023-40032MEDIUM5.5libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libv...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now