2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6156 | HIGH | 8.8 | 0.9% | Nov 22, 2023 | Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37... |
| CVE-2023-47315 | HIGH | 8.8 | 0.8% | Nov 22, 2023 | Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is ha... |
| CVE-2023-6009 | HIGH | 8.8 | 0.9% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to in... |
| CVE-2023-5466 | HIGH | 8.8 | 0.8% | Nov 22, 2023 | The Wp anything slider plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,... |
| CVE-2023-5465 | HIGH | 8.8 | 0.8% | Nov 22, 2023 | The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to... |
| CVE-2023-47350 | HIGH | 8.8 | 0.4% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in SwiftyEdit Content Management System prior to v1.2.0, allows remote a... |
| CVE-2023-2841 | HIGH | 7.2 | 0.6% | Nov 22, 2023 | The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id para... |
| CVE-2023-2497 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. Th... |
| CVE-2023-2440 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th... |
| CVE-2023-2437 | HIGH | 8.1 | 6.8% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is... |
| CVE-2023-26542 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Exeebit phpinfo() WP plugin <= 4.0 versions. |
| CVE-2023-6252 | HIGH | 7.5 | 0.9% | Nov 22, 2023 | Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter. This vulnerability could a... |
| CVE-2023-28747 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in codeboxr CBX Currency Converter plugin <= 3.0.3 versions. |
| CVE-2023-27633 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Customify – Intuitive Website Styling plugin <= 2.10.4 ver... |
| CVE-2023-27461 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Yoohoo Plugins When Last Login plugin <= 1.2.1 versions. |
| CVE-2023-27458 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream plugin <= 4.4.10 versions. |
| CVE-2023-27457 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Passionate Brains Add Expires Headers & Optimized Minify plugin <= 2.... |
| CVE-2023-27453 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.3.1 versions. |
| CVE-2023-27451 | HIGH | 8.8 | 0.8% | Nov 22, 2023 | Server-Side Request Forgery (SSRF) vulnerability in Darren Cooney Instant Images plugin <= 5.1.0.2 versions. |
| CVE-2023-27446 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Fluenx DeepL API translation plugin <= 2.1.4 versions. |
| CVE-2023-27444 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Pierre Lannoy / PerfOps One DecaLog plugin <= 3.7.0 versions. |
| CVE-2023-27442 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.29.2 versions. |
| CVE-2023-26535 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WPPOOL Sheets To WP Table Live Sync plugin <= 2.12.15 versions. |
| CVE-2023-26532 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes Social Auto Poster plugin <= 2.1.4 versions. |
| CVE-2023-28749 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now