2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-45656HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Kevin Weber Lazy Load for Videos plugin <= 2.18.2 versions.
CVE-2023-45655HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions.
CVE-2023-45654HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions.
CVE-2023-45653HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Galaxy Weblinks Video Playlist For YouTube plugin <= 6.0 versions.
CVE-2023-45651HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi WP Attachments allows Cross Site Request Forgery.This is...
CVE-2023-45650HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Fla-shop.Com HTML5 Maps plugin <= 1.7.1.4 versions.
CVE-2023-45638HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in euPago Eupago Gateway For Woocommerce plugin <= 3.1.9 versions.
CVE-2023-45629HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= ...
CVE-2023-45606HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Lasso Simple URLs plugin <= 120 versions.
CVE-2023-45605HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Christopher Finke Feed Statistics plugin <= 4.1 versions.
CVE-2023-45274HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in SendPulse SendPulse Free Web Push plugin <= 1.3.1 versions.
CVE-2023-45273HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Matt McKenny Stout Google Calendar plugin <= 1.2.3 versions.
CVE-2023-43667HIGH7.5Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apac...
CVE-2023-3392HIGH7.2The Read More & Accordion WordPress plugin before 3.2.7 unserializes user input provided via the settings, which could a...
CVE-2023-21415HIGH8.1Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to pa...
CVE-2023-21413HIGH7.2GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of A...
CVE-2023-45898HIGH7.8The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
CVE-2023-38280HIGH7.8IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges ...
CVE-2023-40377HIGH7.8Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege escalation vulnerabil...
CVE-2023-35018HIGH7.2IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validati...
CVE-2023-5590HIGH7.5NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.
CVE-2023-38312HIGH7.5A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game s...
CVE-2023-40378HIGH7.8IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line...
CVE-2023-5586HIGH7.8NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV.
CVE-2023-45871HIGH7.5An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux kernel before 6.5.3....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now