2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6369 | MEDIUM | 5.4 | 0.5% | Jan 11, 2024 | The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification... |
| CVE-2023-6316 | CRITICAL | 9.8 | 1.4% | Jan 11, 2024 | The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in ... |
| CVE-2023-6266 | HIGH | 7.5 | 2.1% | Jan 11, 2024 | The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file... |
| CVE-2023-6220 | CRITICAL | 9.8 | 1.4% | Jan 11, 2024 | The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation ... |
| CVE-2023-5691 | MEDIUM | 4.8 | 0.3% | Jan 11, 2024 | The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio... |
| CVE-2023-5504 | HIGH | 8.7 | 0.9% | Jan 11, 2024 | The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the L... |
| CVE-2023-52032 | CRITICAL | 9.8 | 1.6% | Jan 11, 2024 | TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via th... |
| CVE-2023-52031 | CRITICAL | 9.8 | 1.5% | Jan 11, 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
| CVE-2023-52030 | CRITICAL | 9.8 | 1.5% | Jan 11, 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
| CVE-2023-52029 | CRITICAL | 9.8 | 1.7% | Jan 11, 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
| CVE-2023-52028 | CRITICAL | 9.8 | 1.7% | Jan 11, 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
| CVE-2023-52027 | CRITICAL | 9.8 | 1.7% | Jan 11, 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the ... |
| CVE-2023-4962 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Video PopUp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'video_popup' shortcode in version... |
| CVE-2023-4960 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in ve... |
| CVE-2023-4372 | MEDIUM | 5.4 | 19.7% | Jan 11, 2024 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in version... |
| CVE-2023-4248 | MEDIUM | 4.3 | 0.2% | Jan 11, 2024 | The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th... |
| CVE-2023-4247 | MEDIUM | 5.4 | 0.3% | Jan 11, 2024 | The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th... |
| CVE-2023-4246 | MEDIUM | 4.3 | 0.2% | Jan 11, 2024 | The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. Th... |
| CVE-2023-37644 | MEDIUM | 5.5 | 0.3% | Jan 11, 2024 | SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstr... |
| CVE-2023-6883 | MEDIUM | 4.3 | 0.3% | Jan 11, 2024 | The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2023-6699 | HIGH | 7.5 | 0.9% | Jan 11, 2024 | The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions... |
| CVE-2023-6520 | MEDIUM | 4.3 | 0.2% | Jan 11, 2024 | The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in... |
| CVE-2023-6506 | MEDIUM | 4.3 | 0.5% | Jan 11, 2024 | The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Refere... |
| CVE-2023-6446 | MEDIUM | 4.8 | 0.3% | Jan 11, 2024 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v... |
| CVE-2023-6223 | MEDIUM | 4.3 | 0.3% | Jan 11, 2024 | The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now