2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0630 | HIGH | 8.8 | 5.1% | Mar 20, 2023 | The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that conca... |
| CVE-2023-0370 | MEDIUM | 5.4 | 0.5% | Mar 20, 2023 | The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before... |
| CVE-2023-0369 | MEDIUM | 5.4 | 0.4% | Mar 20, 2023 | The GoToWP WordPress plugin through 5.1.1 does not validate and escape some of its shortcode attributes before outputtin... |
| CVE-2023-0365 | MEDIUM | 5.4 | 0.5% | Mar 20, 2023 | The React Webcam WordPress plugin through 1.2.0 does not validate and escape some of its shortcode attributes before out... |
| CVE-2023-0364 | MEDIUM | 5.4 | 0.5% | Mar 20, 2023 | The real.Kit WordPress plugin before 5.1.1 does not validate and escape some of its shortcode attributes before outputti... |
| CVE-2023-0340 | HIGH | 8.8 | 1.0% | Mar 20, 2023 | The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which coul... |
| CVE-2023-0273 | MEDIUM | 5.4 | 0.4% | Mar 20, 2023 | The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attribute... |
| CVE-2023-0175 | MEDIUM | 5.4 | 0.5% | Mar 20, 2023 | The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its s... |
| CVE-2023-0167 | MEDIUM | 5.4 | 0.5% | Mar 20, 2023 | The GetResponse for WordPress plugin through 5.5.31 does not validate and escape some of its shortcode attributes before... |
| CVE-2023-0145 | MEDIUM | 5.4 | 0.5% | Mar 20, 2023 | The Saan World Clock WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before o... |
| CVE-2023-28429 | MEDIUM | 6.1 | 0.5% | Mar 20, 2023 | Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip f... |
| CVE-2023-28428 | LOW | 3.3 | 0.2% | Mar 20, 2023 | PDFio is a C library for reading and writing PDF files. In versions 1.1.0 and prior, a denial of service vulnerability e... |
| CVE-2023-1515 | MEDIUM | 5.4 | 0.3% | Mar 20, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.19. |
| CVE-2023-28426 | — | — | — | Mar 20, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: GHSA-xrqq-wqh4-5hg2. Reason: Further investigation showed... |
| CVE-2023-28424 | CRITICAL | 9.8 | 1.1% | Mar 20, 2023 | Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and ... |
| CVE-2023-28118 | HIGH | 7.5 | 1.0% | Mar 20, 2023 | kaml provides YAML support for kotlinx.serialization. Prior to version 0.53.0, applications that use kaml to parse untru... |
| CVE-2023-26513 | HIGH | 7.5 | 1.5% | Mar 20, 2023 | Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache S... |
| CVE-2023-0320 | MEDIUM | 5.4 | 0.3% | Mar 20, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Izmir Katip Celebi... |
| CVE-2023-23721 | HIGH | 8.8 | 0.3% | Mar 20, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in David Gwyer Admin Log plugin <= 1.50 versions. |
| CVE-2023-23718 | MEDIUM | 4.8 | 0.4% | Mar 20, 2023 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Esstat17 Page Loading Effects plugin <= 2.0.0 versions. |
| CVE-2023-22682 | MEDIUM | 6.1 | 0.4% | Mar 20, 2023 | Reflected Cross-Site Scripting (XSS) vulnerability in Manuel Masia | Pixedelic.Com Camera slideshow plugin <= 1.4.0.1 ve... |
| CVE-2023-22680 | MEDIUM | 4.8 | 0.4% | Mar 20, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Altanic No API Amazon Affiliate plugin <= 4.2.2 versio... |
| CVE-2023-22679 | MEDIUM | 4.8 | 0.4% | Mar 20, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nicolas Lemoine WP Better Emails plugin <= 0.4 version... |
| CVE-2023-22678 | HIGH | 8.8 | 0.3% | Mar 20, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Rafael Dery Superior FAQ plugin <= 1.0.2 versions. |
| CVE-2023-25795 | MEDIUM | 4.8 | 0.4% | Mar 20, 2023 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in WP-master.Ir Feed Changer & Remover plugin <= 0.2 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now