2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2276CRITICAL9.8The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure...
CVE-2023-2736HIGH8The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9....
CVE-2023-2735MEDIUM5.4The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gh_form' shortcode in versions...
CVE-2023-2717MEDIUM4.3The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9....
CVE-2023-2716MEDIUM5.4The Groundhogg plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missi...
CVE-2023-2715MEDIUM4.3The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2023-2714MEDIUM4.3The Groundhogg plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2023-28623LOW3.7Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBa...
CVE-2023-32677LOW3.1Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zu...
CVE-2023-32679HIGH7.2Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension ...
CVE-2023-32675MEDIUM5.3Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In contracts with more than one regular no...
CVE-2023-2815CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Online Jewelry Store 1.0. Affected by this vulnerabil...
CVE-2023-2814MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Class Scheduling System 1.0. Affected is an u...
CVE-2023-1996MEDIUM6.1A reflected Cross-site Scripting (XSS) vulnerability in Release 3DEXPERIENCE R2018x through Release 3DEXPERIENCE R2023x ...
CVE-2023-28950MEDIUM5.5IBM MQ 8.0, 9.0, 9.1, 9.2, and 9.3 could disclose sensitive user information from a trace file if that functionality has...
CVE-2023-28529MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to ...
CVE-2023-22878MEDIUM5.5IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. I...
CVE-2023-30775MEDIUM5.5A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSampl...
CVE-2023-30774MEDIUM5.5A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES...
CVE-2023-28514MEDIUM5.5IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical e...
CVE-2023-20881HIGH8.1Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override othe...
CVE-2023-31757MEDIUM5.4DedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian'
CVE-2023-31707CRITICAL9.8SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
CVE-2023-30199HIGH7.5Prestashop customexporter <= 1.7.20 is vulnerable to Incorrect Access Control via modules/customexporter/downloads/downl...
CVE-2023-31862MEDIUM5.4jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is on...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now