2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0551MEDIUM5.4The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action...
CVE-2023-0274MEDIUM5.4The URL Params WordPress plugin before 2.5 does not validate and escape some of its shortcode attributes before outputti...
CVE-2023-0058MEDIUM6.1The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when creating and editing its shortcode, and is m...
CVE-2023-4241HIGH7.5lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affecte...
CVE-2023-30871MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PT Woo Plugins (by Webdados) Stock Exporter for WooCommerc...
CVE-2023-30779MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jonathan Daggerhart Query Wrangler plugin <= 1.5.51 versio...
CVE-2023-30786MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Benjamin Guy Captcha Them All plugin <= 1.3.3 versions...
CVE-2023-30785MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Video Grid plugin <= 1.21 versions...
CVE-2023-30784MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kaya Studio Kaya QR Code Generator plugin <= 1.5...
CVE-2023-30782MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions.
CVE-2023-30473MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov YML for Yandex Market plugin <= 3.10.7 vers...
CVE-2023-39507MEDIUM6.1Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a...
CVE-2023-4374MEDIUM4.3The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a...
CVE-2023-3958MEDIUM5.4The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' ...
CVE-2023-26140MEDIUM6.1Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded link...
CVE-2023-39851CRITICAL9.8webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE:...
CVE-2023-39850CRITICAL9.8Schoolmate v1.3 was discovered to contain multiple SQL injection vulnerabilities via the $courseid and $teacherid parame...
CVE-2023-39849Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-20564MEDIUM6.7 Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privil...
CVE-2023-20560MEDIUM4.4 Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privi...
CVE-2023-39852CRITICAL9.8Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NO...
CVE-2023-39848Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-39843LOW2.4Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via bri...
CVE-2023-39842LOW2.4Missing encryption in the RFID tag of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to create a cloned ...
CVE-2023-39841MEDIUM4.6Missing encryption in the RFID tag of Etekcity 3-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via b...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now