2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2811 | MEDIUM | 4.8 | 0.4% | Jun 19, 2023 | The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow hi... |
| CVE-2023-2805 | HIGH | 7.2 | 0.9% | Jun 19, 2023 | The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_a... |
| CVE-2023-2779 | MEDIUM | 6.1 | 6.0% | Jun 19, 2023 | The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parame... |
| CVE-2023-2751 | MEDIUM | 5.3 | 0.5% | Jun 19, 2023 | The Upload Resume WordPress plugin through 1.2.0 does not validate the captcha parameter when uploading a resume via the... |
| CVE-2023-2742 | MEDIUM | 4.8 | 0.5% | Jun 19, 2023 | The AI ChatBot WordPress plugin before 4.5.5 does not sanitize and escape its settings, allowing high-privilege users su... |
| CVE-2023-2719 | HIGH | 8.8 | 1.2% | Jun 19, 2023 | The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in ... |
| CVE-2023-2684 | MEDIUM | 4.8 | 0.4% | Jun 19, 2023 | The File Renaming on Upload WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could... |
| CVE-2023-2654 | MEDIUM | 6.1 | 0.5% | Jun 19, 2023 | The Conditional Menus WordPress plugin before 1.2.1 does not escape a parameter before outputting it back in an attribut... |
| CVE-2023-2600 | MEDIUM | 4.8 | 0.5% | Jun 19, 2023 | The Custom Base Terms WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, which could allow... |
| CVE-2023-2527 | MEDIUM | 4.8 | 0.4% | Jun 19, 2023 | The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and esca... |
| CVE-2023-2492 | HIGH | 7.2 | 0.9% | Jun 19, 2023 | The QueryWall: Plug'n Play Firewall WordPress plugin through 1.1.1 does not properly sanitise and escape a parameter bef... |
| CVE-2023-2401 | MEDIUM | 4.8 | 0.4% | Jun 19, 2023 | The QuBot WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could allow high privil... |
| CVE-2023-2399 | MEDIUM | 6.1 | 0.5% | Jun 19, 2023 | The QuBot WordPress plugin before 1.1.6 doesn't filter user input on chat, leading to bad code inserted on it be reflect... |
| CVE-2023-2359 | HIGH | 8.8 | 2.5% | Jun 19, 2023 | The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an ar... |
| CVE-2023-2221 | HIGH | 7.2 | 0.9% | Jun 19, 2023 | The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a... |
| CVE-2023-29546 | MEDIUM | 6.5 | 0.5% | Jun 19, 2023 | When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden,... |
| CVE-2023-29545 | MEDIUM | 6.5 | 0.6% | Jun 19, 2023 | Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable n... |
| CVE-2023-29542 | CRITICAL | 9.8 | 0.9% | Jun 19, 2023 | A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious fil... |
| CVE-2023-29534 | CRITICAL | 9.1 | 0.7% | Jun 19, 2023 | Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have ... |
| CVE-2023-25747 | HIGH | 7.5 | 0.6% | Jun 19, 2023 | A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below versi... |
| CVE-2023-25736 | CRITICAL | 9.8 | 0.7% | Jun 19, 2023 | An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affe... |
| CVE-2023-25733 | HIGH | 7.5 | 0.6% | Jun 19, 2023 | The return value from `gfx::SourceSurfaceSkia::Map()` wasn't being verified which could have potentially lead to a null ... |
| CVE-2023-0489 | MEDIUM | 5.4 | 0.4% | Jun 19, 2023 | The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outp... |
| CVE-2023-0368 | MEDIUM | 5.4 | 0.4% | Jun 19, 2023 | The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate ... |
| CVE-2023-32216 | CRITICAL | 9.8 | 0.8% | Jun 19, 2023 | Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team repo... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now