2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-52048MEDIUM4.7RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/.
CVE-2023-51692MEDIUM4.3Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for W...
CVE-2023-51533MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwi...
CVE-2023-51681MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issu...
CVE-2023-6917MEDIUM6.7A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels ...
CVE-2023-6922MEDIUM6.5The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu...
CVE-2023-50303MEDIUM6.1IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2023-50380MEDIUM6.5XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, whi...
CVE-2023-48682MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect...
CVE-2023-48681MEDIUM6.1Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acroni...
CVE-2023-48680MEDIUM5.5Sensitive information disclosure due to excessive collection of system information. The following products are affected:...
CVE-2023-48679MEDIUM5.4Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products ...
CVE-2023-48678MEDIUM5.5Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber ...
CVE-2023-7203MEDIUM6.1The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow us...
CVE-2023-7202MEDIUM6.1The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX ...
CVE-2023-7198MEDIUM4.3The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_...
CVE-2023-7167MEDIUM6.1The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-7115MEDIUM4.8The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could...
CVE-2023-7033MEDIUM5.3Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU ...
CVE-2023-52473MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix NULL pointer dereference in zone...
CVE-2023-52472MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: rsa - add a check for allocation failure S...
CVE-2023-52471MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ice: Fix some null pointer dereference issues in ic...
CVE-2023-52470MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/radeon: check the alloc_workqueue return value ...
CVE-2023-52467MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mfd: syscon: Fix null pointer dereference in of_sys...
CVE-2023-52465MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: power: supply: Fix null pointer dereference in smb2...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now