2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-40148MEDIUM6.5Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and ...
CVE-2023-6993MEDIUM6.4The Custom post types, Custom Fields & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2023-6965MEDIUM4.3The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions u...
CVE-2023-6964MEDIUM6.4The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request...
CVE-2023-6799MEDIUM5.9The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure i...
CVE-2023-6777MEDIUM6.5The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in ver...
CVE-2023-6695MEDIUM6.5The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2023-6694MEDIUM5.4The Beaver Themer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all...
CVE-2023-6486MEDIUM5.4The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custo...
CVE-2023-48784MEDIUM6.7A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 a...
CVE-2023-47542MEDIUM6.7A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and be...
CVE-2023-47541MEDIUM6.7An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox...
CVE-2023-47540MEDIUM6.7An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ...
CVE-2023-50821MEDIUM6.9A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC04), SIMATIC WinCC Runtime Professi...
CVE-2023-52385MEDIUM6.2Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect ...
CVE-2023-52364MEDIUM6.3Vulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful exploitation of thi...
CVE-2023-52554MEDIUM6.5Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affe...
CVE-2023-52551MEDIUM5.3Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability ma...
CVE-2023-52544MEDIUM4.3Vulnerability of file path verification being bypassed in the email module. Impact: Successful exploitation of this vuln...
CVE-2023-52543MEDIUM6.2Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will a...
CVE-2023-52542MEDIUM6.5Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will a...
CVE-2023-52536MEDIUM4.4In faceid service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial...
CVE-2023-52535MEDIUM4.4In vsp driver, there is a possible missing verification incorrect input. This could lead to local denial of service with...
CVE-2023-52534MEDIUM5.9In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of ser...
CVE-2023-52533MEDIUM5.3In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now