2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-30752MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Silvia Pfeiffer and Andrew Nimmo External Videos plugi...
CVE-2023-30751MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in iControlWP Article Directory Redux plugin <= 1.0.2 ver...
CVE-2023-30749MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ihomefinder Optima Express + MarketBoost IDX Plugin pl...
CVE-2023-30489MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <=...
CVE-2023-28535MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paytm Paytm Payment Donation plugin <= 2.2.0 versions.
CVE-2023-30483MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <= 3.3.9.2 versions.
CVE-2023-30477MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Essitco AFFILIATE Solution plugin <= 1.0 versions.
CVE-2023-30475MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Elliot Sowersby, RelyWP WooCommerce Affiliate Plugin – Cou...
CVE-2023-29097MEDIUM4.8Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in a3rev Software a3 Portfolio plugin <= 3.1.0 versions.
CVE-2023-37070MEDIUM4.8Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-30188HIGH7.5Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a den...
CVE-2023-30187CRITICAL9.8An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to...
CVE-2023-30186CRITICAL9.8A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitr...
CVE-2023-37847CRITICAL9.8novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
CVE-2023-4321MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.
CVE-2023-3160HIGH7.8 The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or...
CVE-2023-40305MEDIUM5.5GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.
CVE-2023-40303HIGH7.8GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions ...
CVE-2023-3267HIGH8.8When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. T...
CVE-2023-3266CRITICAL9.8A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all ...
CVE-2023-3265CRITICAL9.8An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the user...
CVE-2023-3264CRITICAL9.8The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactio...
CVE-2023-3263HIGH7.5The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the ...
CVE-2023-40296HIGH7.5async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when proce...
CVE-2023-40295HIGH8.8libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_strInitUtf8 at string.c.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now