2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3962 | MEDIUM | 6.1 | 0.4% | Oct 20, 2023 | The Winters theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up t... |
| CVE-2023-3933 | MEDIUM | 6.1 | 0.4% | Oct 20, 2023 | The Your Journey theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions... |
| CVE-2023-46287 | MEDIUM | 6.1 | 0.5% | Oct 20, 2023 | XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php. |
| CVE-2023-5618 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in ver... |
| CVE-2023-44483 | MEDIUM | 6.5 | 1.2% | Oct 20, 2023 | All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, a... |
| CVE-2023-44256 | MEDIUM | 6.5 | 1.2% | Oct 20, 2023 | A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2... |
| CVE-2023-34044 | MEDIUM | 6 | 0.2% | Oct 20, 2023 | VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that... |
| CVE-2023-5615 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-statu... |
| CVE-2023-5534 | MEDIUM | 5.4 | 0.2% | Oct 20, 2023 | The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 ... |
| CVE-2023-5337 | MEDIUM | 5.4 | 0.3% | Oct 20, 2023 | The Contact form Form For All plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortco... |
| CVE-2023-5292 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acfe_for... |
| CVE-2023-5231 | MEDIUM | 5.4 | 0.3% | Oct 20, 2023 | The Magic Action Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to,... |
| CVE-2023-5121 | MEDIUM | 4.8 | 0.3% | Oct 20, 2023 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set... |
| CVE-2023-5109 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The WP Mailto Links – Protect Email Addresses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wpm... |
| CVE-2023-5086 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Copy Anything to Clipboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'copy' shortcode in... |
| CVE-2023-5070 | MEDIUM | 6.5 | 1.2% | Oct 20, 2023 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposu... |
| CVE-2023-4961 | MEDIUM | 5.4 | 0.5% | Oct 20, 2023 | The Poptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'poptin-form' shortcode in versions up ... |
| CVE-2023-4941 | MEDIUM | 4.3 | 0.5% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ... |
| CVE-2023-4926 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4924 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ... |
| CVE-2023-4923 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4796 | MEDIUM | 4.3 | 0.6% | Oct 20, 2023 | The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in v... |
| CVE-2023-4648 | MEDIUM | 4.8 | 0.3% | Oct 20, 2023 | The WP Customer Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions... |
| CVE-2023-4021 | MEDIUM | 4.8 | 0.3% | Oct 20, 2023 | The Modern Events Calendar lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Google API key and... |
| CVE-2023-3998 | MEDIUM | 5.3 | 0.4% | Oct 20, 2023 | The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now