2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-6373HIGH8.8The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting th...
CVE-2023-5922HIGH7.5The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via a...
CVE-2023-4797HIGH7.2The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended...
CVE-2023-4703HIGH7.5The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating us...
CVE-2023-4536HIGH8.8The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing ...
CVE-2023-45237HIGH7.5EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited...
CVE-2023-45236HIGH7.5EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited...
CVE-2023-45235HIGH8.8EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a...
CVE-2023-45234HIGH8.8EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv...
CVE-2023-45233HIGH7.5EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Opt...
CVE-2023-45232HIGH7.5EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination ...
CVE-2023-45230HIGH8.8EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. T...
CVE-2023-2655HIGH7.2The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using i...
CVE-2023-1405HIGH7.5The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform P...
CVE-2023-52105HIGH7.5The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect ava...
CVE-2023-52104HIGH7.5Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affe...
CVE-2023-52102HIGH7.5Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affe...
CVE-2023-52100HIGH7.5The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affec...
CVE-2023-52099HIGH7.5Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulne...
CVE-2023-34063HIGH8.3Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vu...
CVE-2023-52116HIGH7.5Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerabilit...
CVE-2023-52115HIGH7.5The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the...
CVE-2023-52114HIGH7.5Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect ...
CVE-2023-52108HIGH7.5Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this v...
CVE-2023-52107HIGH7.5Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerabilit...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now