2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3118MEDIUM6.1The Export All URLs WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting them back in ...
CVE-2023-3077CRITICAL9.8The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement...
CVE-2023-3076CRITICAL9.8The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of thei...
CVE-2023-3045CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tise Technology Pa...
CVE-2023-37392HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Deepak Anand WP Dummy Content Generator plugin <= 2.3.0 versions.
CVE-2023-37153MEDIUM6.1KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation fe...
CVE-2023-37152CRITICAL9.8Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the admi...
CVE-2023-37151Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2246. Reason: This candidate is a reservation du...
CVE-2023-37150MEDIUM6.1Sourcecodester Online Pizza Ordering System v1.0 has a Cross-site scripting (XSS) vulnerability in "/admin/index.php?pag...
CVE-2023-36935Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-36691HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Albert Peschar WebwinkelKeur plugin <= 3.24 versions.
CVE-2023-36376MEDIUM4.8Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scr...
CVE-2023-36360Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-35912HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Potent Donations for WooCommerce plugin <= 1.1.9 versions.
CVE-2023-35887MEDIUM4.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In ...
CVE-2023-35699MEDIUM4.6Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device t...
CVE-2023-35698MEDIUM5.3Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the F...
CVE-2023-35697HIGH7.5Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-fo...
CVE-2023-35696HIGH7.5Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive info...
CVE-2023-34682Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-34442LOW3.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This...
CVE-2023-32254HIGH8.1A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within t...
CVE-2023-32250HIGH8.1A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within t...
CVE-2023-30449HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic...
CVE-2023-30448HIGH7.5IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now