2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32598MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in A. R. Jones Featured Image Pro Post Grid plugin <= 5.14 ve...
CVE-2023-32596MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wolfgang Ertl weebotLite plugin <= 1.0.0 versions.
CVE-2023-32595MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Palasthotel by Edward Bock, Katharina Rompf Sunny Sear...
CVE-2023-32575MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for Wo...
CVE-2023-24394MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy iframe popup plugin <= 3.3 versions.
CVE-2023-4478HIGH8.2Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to re...
CVE-2023-25981MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form plugin <= 2.8.1 versions.
CVE-2023-25649HIGH8.8 There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_D...
CVE-2023-3425MEDIUM5.3Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS ...
CVE-2023-3406MEDIUM6.5Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS...
CVE-2023-32591MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cloud Primero B.V DBargain plugin <= 3.0.0 versions.
CVE-2023-32584MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in John Newcombe eBecas plugin <= 3.1.3 versions.
CVE-2023-32577MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eji Osigwe DevBuddy Twitter Feed plugin <= 4.0.0 versi...
CVE-2023-32576MEDIUM5.4Auth. (subscriber+) Stored Cross-Site Scripting') vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.18 v...
CVE-2023-32518MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ono Oogami WP Chinese Conversion plugin <= 1.1.16 versions...
CVE-2023-32757CRITICAL9.8 e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenti...
CVE-2023-32756HIGH7.5 e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An ...
CVE-2023-41173HIGH7.5AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.
CVE-2023-32755MEDIUM5.3 e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtai...
CVE-2023-40530MEDIUM4.7Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skyl...
CVE-2023-4520MEDIUM6.1The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_use...
CVE-2023-40599HIGH7.5Regular expression Denial-of-Service (ReDoS) exists in multiple add-ons for Mailform Pro CGI 4.3.1.3 and earlier, which ...
CVE-2023-40577MEDIUM5.4Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission t...
CVE-2023-40570MEDIUM5.3Datasette is an open source multi-tool for exploring and publishing data. This bug affects Datasette instances running a...
CVE-2023-40217MEDIUM5.3An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. I...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now