2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-47530HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPVibes Redirect 4...
CVE-2023-47506HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Master slider Mast...
CVE-2023-34168HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Raven WP Repo...
CVE-2023-33331HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Produc...
CVE-2023-6355MEDIUM6.8 Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechani...
CVE-2023-49148HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Kulwant Nagi Affiliate Booster – Pros & Cons, Notice, and CTA Blocks ...
CVE-2023-48781HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Marketing Rapel MkRapel Regiones y Ciudades de Chile para WC.This iss...
CVE-2023-48778HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Product Size Chart For WooCommerce.This issue affects Prod...
CVE-2023-48773HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WP Doctor WooCommerce Login Redirect.This issue affects WooCommerce L...
CVE-2023-48772HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Prevent Landscape Rotation.This issue affects Prevent L...
CVE-2023-48769HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Blue Coral Chat Bubble – Floating Chat with Contact Chat Icons, Messa...
CVE-2023-48768HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in CodeAstrology Team Quantity Plus Minus Button for WooCommerce by Code...
CVE-2023-46686HIGH7.1 A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallaghe...
CVE-2023-41967MEDIUM4.6 Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacke...
CVE-2023-24590HIGH8.8 A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memor...
CVE-2023-23584MEDIUM4.3 An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to ...
CVE-2023-23576MEDIUM4.3 Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site ...
CVE-2023-23570HIGH8.1 Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid con...
CVE-2023-22439MEDIUM4.3 Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web in...
CVE-2023-40691MEDIUM4.9IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21...
CVE-2023-6295HIGH7.2The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate pa...
CVE-2023-6289MEDIUM4.3The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings,...
CVE-2023-6272CRITICAL9.8The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attac...
CVE-2023-6222HIGH7.2IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which coul...
CVE-2023-6203HIGH7.5The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now