2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-50982CRITICAL9Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in...
CVE-2023-47890HIGH8.8pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.
CVE-2023-6845HIGH8.8The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to ...
CVE-2023-6750HIGH7.5The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a...
CVE-2023-6631HIGH7.8PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to ...
CVE-2023-6627MEDIUM6.1The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API r...
CVE-2023-6555MEDIUM6.1The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting i...
CVE-2023-6532HIGH8.8The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, whi...
CVE-2023-6529MEDIUM6.1The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing un...
CVE-2023-6528HIGH8.8The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unseriali...
CVE-2023-6505HIGH7.5The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive di...
CVE-2023-6383HIGH7.5The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which all...
CVE-2023-6161MEDIUM6.1The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in ...
CVE-2023-6141MEDIUM5.4The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, whi...
CVE-2023-6140HIGH8.8The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like...
CVE-2023-6139MEDIUM6.5The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, whi...
CVE-2023-6042HIGH7.5Any unauthenticated user may send e-mail from the site with any title or content to the admin
CVE-2023-5957HIGH7.2The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image file...
CVE-2023-5911MEDIUM4.8The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its se...
CVE-2023-5235HIGH8.8The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its A...
CVE-2023-52222HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a throu...
CVE-2023-52208HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This...
CVE-2023-52207HIGH8.8Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affe...
CVE-2023-52190HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Swings Coupon Referral Program.This issue...
CVE-2023-1032MEDIUM5.5The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now