2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-31071MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yannick Lefebvre Modal Dialog plugin <= 3.5.14 versions.
CVE-2023-30877MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov XML for Google Merchant Center plugin <= 3....
CVE-2023-30876MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dave Ross Dave's WordPress Live Search plugin <= 4.8.1...
CVE-2023-30874MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Steve Curtis, St. Pete Design Gps Plotter plugin <= 5....
CVE-2023-28622MEDIUM5.4Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Trident Technolabs Easy Slider Revolution plugin <= 1...
CVE-2023-28533MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in M Williams Cab Grid plugin <= 1.5.15 versions.
CVE-2023-40281MEDIUM4.8EC-CUBE 2.11.0 to 2.17.2-p1 contain a cross-site scripting vulnerability in "mail/template" and "products/product" of Ma...
CVE-2023-40252CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V...
CVE-2023-40251MEDIUM5.9Missing Encryption of Sensitive Data vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian N...
CVE-2023-3244MEDIUM4.3The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2023-34217HIGH8.1TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to ...
CVE-2023-34216HIGH8.1TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to ...
CVE-2023-34215CRITICAL9.8TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerabilit...
CVE-2023-4395MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
CVE-2023-4392MEDIUM5.3A vulnerability was found in Control iD Gerencia Web 1.30 and classified as problematic. Affected by this issue is some ...
CVE-2023-34214CRITICAL9.8TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to ...
CVE-2023-34213CRITICAL9.8TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability st...
CVE-2023-33239CRITICAL9.8TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to ...
CVE-2023-33238CRITICAL9.8TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to ...
CVE-2023-25647LOW3.3 There is a permission and access control vulnerability in some ZTE mobile phones. Due to improper access control, app...
CVE-2023-33237HIGH8.8TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerabilit...
CVE-2023-35011MEDIUM5.4IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to server-side request forgery (SSRF). This may allow an a...
CVE-2023-35009MEDIUM5.3IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authe...
CVE-2023-39846CRITICAL9.8An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.
CVE-2023-38894CRITICAL9.8A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code vi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now