2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1019MEDIUM5.4The Help Desk WP WordPress plugin through 1.2.0 does not sanitise and escape some parameters, which could allow users wi...
CVE-2023-0892MEDIUM4.8The BizLibrary WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2023-0812HIGH7.5The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or ...
CVE-2023-0763MEDIUM4.3The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting H...
CVE-2023-0762MEDIUM4.3The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting d...
CVE-2023-0761MEDIUM4.3The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting S...
CVE-2023-0644MEDIUM6.1The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various p...
CVE-2023-0600CRITICAL9.8The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenat...
CVE-2023-0520MEDIUM5.4The RapidExpCart WordPress plugin through 1.0 does not sanitize and escape the url parameter in the rapidexpcart endpoin...
CVE-2023-0490MEDIUM5.4The f(x) TOC WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputt...
CVE-2023-0233MEDIUM5.4The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputti...
CVE-2023-31986CRITICAL9.8A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitr...
CVE-2023-23688MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions.
CVE-2023-23683MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ozan Canakli White Label Branding for Elementor Page B...
CVE-2023-23674MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in RVOLA WP Original Media Path plugin <= 2.4.0 versions.
CVE-2023-23654MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SparkPost plugin <= 3.2.5 versions.
CVE-2023-22717MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in nCrafts FormCraft plugin <= 1.2.6 versions.
CVE-2023-22706MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions.
CVE-2023-31409HIGH7.5Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120...
CVE-2023-31408HIGH7.5Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120...
CVE-2023-23450CRITICAL9.8Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 11002...
CVE-2023-23449MEDIUM5.3Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 112011...
CVE-2023-23448MEDIUM5.3Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 110021...
CVE-2023-23447HIGH7.5Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120...
CVE-2023-23446HIGH7.5Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 11225...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now