2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38563HIGH8.8Archer C1200 firmware versions prior to 'Archer C1200(JP)_V2_230508' and Archer C9 firmware versions prior to 'Archer C9...
CVE-2023-37284HIGH8.8Improper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a netwo...
CVE-2023-36489HIGH8.8Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected p...
CVE-2023-32619HIGH8.8Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(J...
CVE-2023-31188HIGH8Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected pro...
CVE-2023-4634CRITICAL9.8The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in vers...
CVE-2023-40601MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versio...
CVE-2023-40560MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versio...
CVE-2023-40554MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post &...
CVE-2023-40553MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Plausible.Io Plausible Analytics plugin <= 1.3.3 versions.
CVE-2023-40552MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gurcharan Singh Fitness calculators plugin plugin <= 2...
CVE-2023-40329MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPZest Custom Admin Login Page | WPZest plugin <= 1.2....
CVE-2023-40328MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Carrrot plugin <= 1.1.0 versions.
CVE-2023-40007MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ujwol Bastakoti CT Commerce plugin <= 2.0.1 versions.
CVE-2023-30497MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Simon Chuang WP LINE Notify plugin <= 1.4.4 versions.
CVE-2023-4705Rejected reason: CVE-2023-4705 was wrongly assigned to a bug that was deemed to be a non-security issue by the Linux ker...
CVE-2023-29441MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Robert Heller WebLibrarian plugin <= 3.5.8.1 versions.
CVE-2023-4779MEDIUM5.4The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery...
CVE-2023-3472HIGH7.8Use after free vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary...
CVE-2023-3471HIGH7.8Buffer overflow vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrar...
CVE-2023-35719MEDIUM6.8ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnera...
CVE-2023-32163HIGH7.8Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attac...
CVE-2023-32162HIGH7.8Wacom Drivers for Windows Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability a...
CVE-2023-4773MEDIUM6.4The WordPress Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wordpress_social_l...
CVE-2023-30730MEDIUM5.5Implicit intent hijacking vulnerability in Camera prior to versions 11.0.16.43 in Android 11, 12.1.00.30, 12.0.07.53, 12...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now