2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2959HIGH7.5Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Pr...
CVE-2023-2701MEDIUM6.1The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, lea...
CVE-2023-2636HIGH8.8The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a S...
CVE-2023-2579MEDIUM5.4The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow use...
CVE-2023-2330HIGH8.8The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access ...
CVE-2023-2329HIGH8.8The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access C...
CVE-2023-2143MEDIUM5.4The Enable SVG, WebP & ICO Upload WordPress plugin through 1.0.3 does not sanitize SVG file contents, leading to a Cross...
CVE-2023-1893MEDIUM6.1The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the...
CVE-2023-0439MEDIUM5.4The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripti...
CVE-2023-2912HIGH7.5Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction.
CVE-2023-27424HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Korol Yuriy aka Shra Inactive User Deleter plugin <= 1.59 versions.
CVE-2023-34036MEDIUM5.3 Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious f...
CVE-2023-27606HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Sajjad Hossain WP Reroute Email plugin <= 1.4.6 versions.
CVE-2023-23719HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Premmerce plugin <= 1.3.17 versions.
CVE-2023-23646HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.
CVE-2023-22672HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Mr.Vibe vSlider Multi Image Slider for WordPress plugin <= 4.1.2 vers...
CVE-2023-26512CRITICAL9.8CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7....
CVE-2023-3700MEDIUM4.3Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
CVE-2023-2760HIGH7.6An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version...
CVE-2023-2759HIGH8.8A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user t...
CVE-2023-3696CRITICAL9.8Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4.
CVE-2023-3695CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. Affected is an un...
CVE-2023-35012MEDIUM6.7IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a...
CVE-2023-3694CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester/projectworlds House Rental and Prope...
CVE-2023-35901MEDIUM5.3IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now