2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-39975HIGH8.8kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated...
CVE-2023-39115CRITICAL9.8install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum...
CVE-2023-38904MEDIUM5.4A Cross Site Scripting (XSS) vulnerability in Netlify CMS v.2.10.192 allows a remote attacker to execute arbitrary code ...
CVE-2023-33663CRITICAL9.8In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can...
CVE-2023-32495HIGH7.8 Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability...
CVE-2023-32493CRITICAL9.8 Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker ...
CVE-2023-32492HIGH7.1 Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker ...
CVE-2023-32491MEDIUM6.5 Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A ...
CVE-2023-32490MEDIUM6.7 Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attack...
CVE-2023-32489MEDIUM6.7 Dell PowerScale OneFS 8.2x -9.5x contains a privilege escalation vulnerability. A local attacker with high privileges c...
CVE-2023-32488MEDIUM4.3 Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacke...
CVE-2023-32487HIGH7.8 Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attack...
CVE-2023-32486HIGH7.8 Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could ...
CVE-2023-32494MEDIUM6.7 Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local pr...
CVE-2023-4381MEDIUM4.3Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-2272MEDIUM6.1The Tiempo.com WordPress plugin through 0.1.2 does not sanitise and escape the page parameter before outputting it back ...
CVE-2023-2271MEDIUM4.3The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when deleting its shortcode, which could allow at...
CVE-2023-2254MEDIUM4.8The Ko-fi Button WordPress plugin before 1.3.3 does not properly some of its settings, which could allow high-privilege ...
CVE-2023-2225MEDIUM4.8The SEO ALert WordPress plugin through 1.59 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-2123MEDIUM6.1The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it ...
CVE-2023-2122MEDIUM6.1The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter ...
CVE-2023-1977HIGH8.8The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for...
CVE-2023-1465MEDIUM6.1The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, lea...
CVE-2023-1110MEDIUM5.4The Yellow Yard Searchbar WordPress plugin before 2.8.12 does not validate and escape some of its shortcode attributes b...
CVE-2023-0579HIGH8.8The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now