2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-41244HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Buildfail Localize Remote Images plugin <= 1.0.9 versions.
CVE-2023-40558HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in eMarket Design YouTube Video Gallery by YouTube Showcase plugin <= 3....
CVE-2023-3350HIGH7.5A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the...
CVE-2023-3349HIGH7.5Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to ret...
CVE-2023-32091HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in POEditor plugin <= 0.9.4 versions.
CVE-2023-27435HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui HTTP Auth plugin <= 0.3.2 versions.
CVE-2023-0506HIGH8.8The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation...
CVE-2023-40202HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Hannes Etzelstorfer // codemiq WP HTML Mail plugin <= 3.4.1 versions.
CVE-2023-40201HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in FuturioWP Futurio Extra plugin <= 1.8.4 versions leads to activation ...
CVE-2023-40199HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab WP Like Button plugin <= 1.7.0 versions.
CVE-2023-2681HIGH8.8An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote...
CVE-2023-4103HIGH8.8QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not c...
CVE-2023-4102HIGH8.8QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficien...
CVE-2023-4100HIGH8.2Allows an attacker to perform XSS attacks stored on certain resources. Exploiting this vulnerability can lead to a DoS c...
CVE-2023-4098HIGH8.8It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS...
CVE-2023-40210HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Sean Barton (Tortoise IT) SB Child List plugin <= 4.5 versions.
CVE-2023-39989HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in 99robots Header Footer Code Manager plugin <= 1.1.34 versions.
CVE-2023-39923HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 7.2.7 versions.
CVE-2023-39917HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery pl...
CVE-2023-39165HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets plugin <= 2.2.8 versions.
CVE-2023-2830HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Trustindex.Io WP Testimonials plugin <= 1.4.2 versions.
CVE-2023-25989HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Me...
CVE-2023-4097HIGH8.8The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, ...
CVE-2023-38398HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Taboola plugin <= 2.0.1 versions.
CVE-2023-38396HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Alain Gonzalez plugin <= 3.1.2 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now