2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4315 | MEDIUM | 6.1 | 0.4% | Aug 31, 2023 | The Woo Custom Emails for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wcemails_edit' parameter in... |
| CVE-2023-4245 | MEDIUM | 4.3 | 0.4% | Aug 31, 2023 | The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capabili... |
| CVE-2023-4161 | MEDIUM | 4.3 | 0.3% | Aug 31, 2023 | The WooCommerce PDF Invoice Builder for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce che... |
| CVE-2023-4160 | MEDIUM | 4.8 | 0.4% | Aug 31, 2023 | The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings... |
| CVE-2023-4000 | MEDIUM | 4.3 | 0.2% | Aug 31, 2023 | The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an... |
| CVE-2023-3999 | MEDIUM | 4.3 | 0.3% | Aug 31, 2023 | The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability c... |
| CVE-2023-3764 | MEDIUM | 4.3 | 0.2% | Aug 31, 2023 | The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, ... |
| CVE-2023-3404 | MEDIUM | 4.9 | 0.6% | Aug 31, 2023 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, ... |
| CVE-2023-2354 | MEDIUM | 5.4 | 0.5% | Aug 31, 2023 | The CHP Ads Block Detector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings reachabl... |
| CVE-2023-2353 | MEDIUM | 4.3 | 0.5% | Aug 31, 2023 | The CHP Ads Block Detector plugin for WordPress is vulnerable to unauthorized plugin settings update and reset due to a ... |
| CVE-2023-2352 | MEDIUM | 4.3 | 0.3% | Aug 31, 2023 | The CHP Ads Block Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu... |
| CVE-2023-2279 | MEDIUM | 5.4 | 0.3% | Aug 31, 2023 | The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ... |
| CVE-2023-2188 | MEDIUM | 4.9 | 0.8% | Aug 31, 2023 | The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and... |
| CVE-2023-2174 | MEDIUM | 4.3 | 0.3% | Aug 31, 2023 | The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2023-2173 | MEDIUM | 4.3 | 0.4% | Aug 31, 2023 | The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7... |
| CVE-2023-2172 | MEDIUM | 4.3 | 0.4% | Aug 31, 2023 | The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7... |
| CVE-2023-2171 | MEDIUM | 5.4 | 0.3% | Aug 31, 2023 | The BadgeOS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions ... |
| CVE-2023-0689 | MEDIUM | 4.3 | 0.5% | Aug 31, 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name'... |
| CVE-2023-4655 | MEDIUM | 6.1 | 0.4% | Aug 31, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1. |
| CVE-2023-4653 | MEDIUM | 4.8 | 0.4% | Aug 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
| CVE-2023-4652 | MEDIUM | 5.4 | 0.4% | Aug 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
| CVE-2023-4651 | MEDIUM | 5.4 | 0.3% | Aug 31, 2023 | Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1. |
| CVE-2023-4650 | MEDIUM | 4.7 | 0.5% | Aug 31, 2023 | Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
| CVE-2023-4649 | MEDIUM | 5.4 | 0.4% | Aug 31, 2023 | Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1. |
| CVE-2023-4163 | MEDIUM | 4.4 | 0.3% | Aug 31, 2023 | In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, le... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now