2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6373 | HIGH | 8.8 | 0.4% | Jan 16, 2024 | The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting th... |
| CVE-2023-6292 | MEDIUM | 4.3 | 0.2% | Jan 16, 2024 | The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its set... |
| CVE-2023-6046 | MEDIUM | 4.8 | 0.4% | Jan 16, 2024 | The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privil... |
| CVE-2023-6005 | MEDIUM | 4.8 | 0.4% | Jan 16, 2024 | The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of it... |
| CVE-2023-5922 | HIGH | 7.5 | 0.7% | Jan 16, 2024 | The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via a... |
| CVE-2023-5558 | MEDIUM | 6.1 | 0.9% | Jan 16, 2024 | The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the ... |
| CVE-2023-4797 | HIGH | 7.2 | 1.0% | Jan 16, 2024 | The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended... |
| CVE-2023-4757 | MEDIUM | 5.4 | 0.4% | Jan 16, 2024 | The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape ... |
| CVE-2023-4703 | HIGH | 7.5 | 0.6% | Jan 16, 2024 | The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating us... |
| CVE-2023-4536 | HIGH | 8.8 | 0.8% | Jan 16, 2024 | The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing ... |
| CVE-2023-45237 | HIGH | 7.5 | 1.0% | Jan 16, 2024 | EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited... |
| CVE-2023-45236 | HIGH | 7.5 | 1.0% | Jan 16, 2024 | EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited... |
| CVE-2023-45235 | HIGH | 8.8 | 1.2% | Jan 16, 2024 | EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a... |
| CVE-2023-45234 | HIGH | 8.8 | 1.2% | Jan 16, 2024 | EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv... |
| CVE-2023-45233 | HIGH | 7.5 | 2.1% | Jan 16, 2024 | EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Opt... |
| CVE-2023-45232 | HIGH | 7.5 | 2.1% | Jan 16, 2024 | EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination ... |
| CVE-2023-45231 | MEDIUM | 6.5 | 0.8% | Jan 16, 2024 | EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redire... |
| CVE-2023-45230 | HIGH | 8.8 | 1.2% | Jan 16, 2024 | EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. T... |
| CVE-2023-45229 | MEDIUM | 6.5 | 0.9% | Jan 16, 2024 | EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option ... |
| CVE-2023-3771 | MEDIUM | 6.1 | 0.5% | Jan 16, 2024 | The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect ... |
| CVE-2023-3647 | MEDIUM | 4.8 | 0.4% | Jan 16, 2024 | The IURNY by INDIGITALL WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could all... |
| CVE-2023-3372 | MEDIUM | 5.4 | 0.5% | Jan 16, 2024 | The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before o... |
| CVE-2023-3211 | CRITICAL | 9.8 | 0.8% | Jan 16, 2024 | The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter be... |
| CVE-2023-3178 | MEDIUM | 4.3 | 0.2% | Jan 16, 2024 | The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could al... |
| CVE-2023-37522 | CRITICAL | 9.8 | 0.4% | Jan 16, 2024 | HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now