2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26131MEDIUM6.1All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/...
CVE-2023-25539CRITICAL9.8 Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticat...
CVE-2023-2836MEDIUM4.8The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up t...
CVE-2023-2434LOW3.8The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on th...
CVE-2023-1661MEDIUM5.4The Display post meta, term meta, comment meta, and user meta plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2023-2987CRITICAL9.8The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptograp...
CVE-2023-2549HIGH8.8The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions starting from 1.0.7 ...
CVE-2023-2547MEDIUM5.4The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check...
CVE-2023-2545HIGH8.8The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che...
CVE-2023-2436MEDIUM4.4The Blog-in-Blog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blog_in_blog' shortcode in v...
CVE-2023-2435HIGH7.2The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via ...
CVE-2023-30197HIGH7.5Incorrect Access Control in the module "My inventory" (myinventory) <= 1.6.6 from Webbax for PrestaShop, allows a guest ...
CVE-2023-2999MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
CVE-2023-2998MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
CVE-2023-23562MEDIUM4.3Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can upd...
CVE-2023-2612MEDIUM4.7Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when ...
CVE-2023-29745HIGH7.1An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attac...
CVE-2023-29742HIGH7.8An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a code execution attack by manipulat...
CVE-2023-28353HIGH8.8An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any typ...
CVE-2023-28352HIGH7.4An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system...
CVE-2023-28351LOW3.3An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with t...
CVE-2023-28350MEDIUM6.1An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized be...
CVE-2023-28349HIGH8.8An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted pr...
CVE-2023-28348HIGH7.4An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in...
CVE-2023-28347CRITICAL9.6An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-c...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now