2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-4315MEDIUM6.1The Woo Custom Emails for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wcemails_edit' parameter in...
CVE-2023-4245MEDIUM4.3The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capabili...
CVE-2023-4161MEDIUM4.3The WooCommerce PDF Invoice Builder for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce che...
CVE-2023-4160MEDIUM4.8The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings...
CVE-2023-4000MEDIUM4.3The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an...
CVE-2023-3999MEDIUM4.3The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability c...
CVE-2023-3764MEDIUM4.3The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, ...
CVE-2023-3404MEDIUM4.9The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, ...
CVE-2023-2354MEDIUM5.4The CHP Ads Block Detector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings reachabl...
CVE-2023-2353MEDIUM4.3The CHP Ads Block Detector plugin for WordPress is vulnerable to unauthorized plugin settings update and reset due to a ...
CVE-2023-2352MEDIUM4.3The CHP Ads Block Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu...
CVE-2023-2279MEDIUM5.4The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ...
CVE-2023-2188MEDIUM4.9The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and...
CVE-2023-2174MEDIUM4.3The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2023-2173MEDIUM4.3The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7...
CVE-2023-2172MEDIUM4.3The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7...
CVE-2023-2171MEDIUM5.4The BadgeOS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions ...
CVE-2023-0689MEDIUM4.3The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name'...
CVE-2023-4655MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1.
CVE-2023-4653MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-4652MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-4651MEDIUM5.4Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1.
CVE-2023-4650MEDIUM4.7Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-4649MEDIUM5.4Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1.
CVE-2023-4163MEDIUM4.4In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, le...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now