2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5177 | MEDIUM | 5.3 | 0.5% | Oct 16, 2023 | The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 exposes the full path of a file when putting in a non-existen... |
| CVE-2023-5167 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activi... |
| CVE-2023-5089 | MEDIUM | 5.3 | 2.2% | Oct 16, 2023 | The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect W... |
| CVE-2023-5087 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher fr... |
| CVE-2023-5057 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which co... |
| CVE-2023-4950 | MEDIUM | 6.1 | 0.5% | Oct 16, 2023 | The Interactive Contact Form and Multi Step Form Builder WordPress plugin before 3.4 does not sanitise and escape some p... |
| CVE-2023-4933 | MEDIUM | 5.3 | 0.5% | Oct 16, 2023 | The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores... |
| CVE-2023-4862 | MEDIUM | 4.8 | 0.4% | Oct 16, 2023 | The File Manager Pro WordPress plugin before 1.8.1 does not adequately validate and escape some inputs, leading to XSS b... |
| CVE-2023-4821 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dan... |
| CVE-2023-4820 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url f... |
| CVE-2023-4819 | MEDIUM | 6.1 | 0.4% | Oct 16, 2023 | The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded ... |
| CVE-2023-4811 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could ... |
| CVE-2023-4805 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users s... |
| CVE-2023-4800 | MEDIUM | 6.5 | 0.9% | Oct 16, 2023 | The DoLogin Security WordPress plugin before 3.7.1 does not restrict the access of a widget that shows the IPs of failed... |
| CVE-2023-4798 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes... |
| CVE-2023-4795 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The Testimonial Slider Shortcode WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attrib... |
| CVE-2023-4783 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The Magee Shortcodes WordPress plugin through 2.1.1 does not validate and escape some of its shortcode attributes before... |
| CVE-2023-4725 | MEDIUM | 4.8 | 0.4% | Oct 16, 2023 | The Simple Posts Ticker WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could all... |
| CVE-2023-4687 | MEDIUM | 6.1 | 0.5% | Oct 16, 2023 | The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post... |
| CVE-2023-4646 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The Simple Posts Ticker WordPress plugin before 1.1.6 does not validate and escape some of its shortcode attributes befo... |
| CVE-2023-4388 | MEDIUM | 4.8 | 0.4% | Oct 16, 2023 | The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privil... |
| CVE-2023-4290 | MEDIUM | 6.1 | 0.4% | Oct 16, 2023 | The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting i... |
| CVE-2023-4289 | MEDIUM | 5.4 | 0.4% | Oct 16, 2023 | The WP Matterport Shortcode WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes ... |
| CVE-2023-45150 | MEDIUM | 4.3 | 0.4% | Oct 16, 2023 | Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server wa... |
| CVE-2023-45149 | MEDIUM | 4.3 | 0.5% | Oct 16, 2023 | Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection of public... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now