2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-50982 | CRITICAL | 9 | 1.3% | Jan 8, 2024 | Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in... |
| CVE-2023-47890 | HIGH | 8.8 | 1.1% | Jan 8, 2024 | pyLoad 0.5.0 is vulnerable to Unrestricted File Upload. |
| CVE-2023-6845 | HIGH | 8.8 | 0.3% | Jan 8, 2024 | The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to ... |
| CVE-2023-6750 | HIGH | 7.5 | 2.0% | Jan 8, 2024 | The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a... |
| CVE-2023-6631 | HIGH | 7.8 | 0.2% | Jan 8, 2024 | PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to ... |
| CVE-2023-6627 | MEDIUM | 6.1 | 0.6% | Jan 8, 2024 | The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API r... |
| CVE-2023-6555 | MEDIUM | 6.1 | 0.4% | Jan 8, 2024 | The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting i... |
| CVE-2023-6532 | HIGH | 8.8 | 0.3% | Jan 8, 2024 | The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, whi... |
| CVE-2023-6529 | MEDIUM | 6.1 | 0.2% | Jan 8, 2024 | The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing un... |
| CVE-2023-6528 | HIGH | 8.8 | 1.4% | Jan 8, 2024 | The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unseriali... |
| CVE-2023-6505 | HIGH | 7.5 | 39.9% | Jan 8, 2024 | The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive di... |
| CVE-2023-6383 | HIGH | 7.5 | 0.6% | Jan 8, 2024 | The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which all... |
| CVE-2023-6161 | MEDIUM | 6.1 | 0.4% | Jan 8, 2024 | The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2023-6141 | MEDIUM | 5.4 | 0.4% | Jan 8, 2024 | The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, whi... |
| CVE-2023-6140 | HIGH | 8.8 | 1.1% | Jan 8, 2024 | The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like... |
| CVE-2023-6139 | MEDIUM | 6.5 | 0.6% | Jan 8, 2024 | The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, whi... |
| CVE-2023-6042 | HIGH | 7.5 | 0.6% | Jan 8, 2024 | Any unauthenticated user may send e-mail from the site with any title or content to the admin |
| CVE-2023-5957 | HIGH | 7.2 | 0.9% | Jan 8, 2024 | The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image file... |
| CVE-2023-5911 | MEDIUM | 4.8 | 0.3% | Jan 8, 2024 | The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its se... |
| CVE-2023-5235 | HIGH | 8.8 | 0.6% | Jan 8, 2024 | The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its A... |
| CVE-2023-52222 | HIGH | 8.8 | 0.3% | Jan 8, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a throu... |
| CVE-2023-52208 | HIGH | 7.5 | 0.4% | Jan 8, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This... |
| CVE-2023-52207 | HIGH | 8.8 | 0.6% | Jan 8, 2024 | Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affe... |
| CVE-2023-52190 | HIGH | 7.5 | 0.5% | Jan 8, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Swings Coupon Referral Program.This issue... |
| CVE-2023-1032 | MEDIUM | 5.5 | 0.3% | Jan 8, 2024 | The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now