2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2984HIGH8.8Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.
CVE-2023-2983HIGH8.8Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.
CVE-2023-2981MEDIUM5.4A vulnerability, which was classified as problematic, has been found in Abstrium Pydio Cells 4.2.0. This issue affects s...
CVE-2023-2980HIGH8.8A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. This vulnerability affects unknown code ...
CVE-2023-2979HIGH8.8A vulnerability classified as critical has been found in Abstrium Pydio Cells 4.2.0. This affects an unknown part of the...
CVE-2023-2978MEDIUM4.3A vulnerability was found in Abstrium Pydio Cells 4.2.0. It has been rated as problematic. Affected by this issue is som...
CVE-2023-2650MEDIUM6.5Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Imp...
CVE-2023-30196HIGH7.5Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download....
CVE-2023-33234HIGH7.2Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar ima...
CVE-2023-2973MEDIUM6.1A vulnerability, which was classified as problematic, has been found in SourceCodester Students Online Internship Timesh...
CVE-2023-2972CRITICAL9.8Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.
CVE-2023-30601HIGH7.8Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user runn...
CVE-2023-2518MEDIUM6.1The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it...
CVE-2023-2470MEDIUM4.8The Add to Feedly WordPress plugin through 1.2.11 does not sanitize and escape its settings, allowing high-privilege use...
CVE-2023-2296MEDIUM6.1The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading t...
CVE-2023-2288HIGH8.8The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operati...
CVE-2023-2287MEDIUM4.3The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo imp...
CVE-2023-2256MEDIUM6.1The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL paramet...
CVE-2023-2223MEDIUM4.8The Login rebuilder WordPress plugin before 2.8.1 does not sanitise and escape some of its settings, which could allow h...
CVE-2023-2117LOW2.7The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_su...
CVE-2023-2113MEDIUM4.8The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export,...
CVE-2023-2111MEDIUM4.9The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL quer...
CVE-2023-2023MEDIUM6.1The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading...
CVE-2023-1938HIGH8.8The WP Fastest Cache WordPress plugin before 1.1.5 does not have CSRF check in an AJAX action, and does not validate use...
CVE-2023-1524MEDIUM6.5The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now