2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6373HIGH8.8The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting th...
CVE-2023-6292MEDIUM4.3The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its set...
CVE-2023-6046MEDIUM4.8The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privil...
CVE-2023-6005MEDIUM4.8The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of it...
CVE-2023-5922HIGH7.5The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via a...
CVE-2023-5558MEDIUM6.1The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the ...
CVE-2023-4797HIGH7.2The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended...
CVE-2023-4757MEDIUM5.4The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape ...
CVE-2023-4703HIGH7.5The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating us...
CVE-2023-4536HIGH8.8The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing ...
CVE-2023-45237HIGH7.5EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited...
CVE-2023-45236HIGH7.5EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited...
CVE-2023-45235HIGH8.8EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a...
CVE-2023-45234HIGH8.8EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv...
CVE-2023-45233HIGH7.5EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Opt...
CVE-2023-45232HIGH7.5EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination ...
CVE-2023-45231MEDIUM6.5EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing  Neighbor Discovery Redire...
CVE-2023-45230HIGH8.8EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. T...
CVE-2023-45229MEDIUM6.5EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option ...
CVE-2023-3771MEDIUM6.1The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect ...
CVE-2023-3647MEDIUM4.8The IURNY by INDIGITALL WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could all...
CVE-2023-3372MEDIUM5.4The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before o...
CVE-2023-3211CRITICAL9.8The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter be...
CVE-2023-3178MEDIUM4.3The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could al...
CVE-2023-37522CRITICAL9.8HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now