2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1404 | MEDIUM | 5.4 | 0.5% | Jun 9, 2023 | The Weaver Show Posts Plugin for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of ... |
| CVE-2023-1403 | MEDIUM | 5.4 | 0.5% | Jun 9, 2023 | The Weaver Xtreme Theme for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the p... |
| CVE-2023-1375 | MEDIUM | 4.3 | 0.5% | Jun 9, 2023 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized cache deletion in versions up to, and including,... |
| CVE-2023-1169 | MEDIUM | 4.3 | 0.6% | Jun 9, 2023 | The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capabili... |
| CVE-2023-0993 | MEDIUM | 4.3 | 0.5% | Jun 9, 2023 | The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the 'theme-plugin-file' AJAX action i... |
| CVE-2023-0992 | MEDIUM | 6.1 | 93.0% | Jun 9, 2023 | The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, ... |
| CVE-2023-0832 | MEDIUM | 4.3 | 0.2% | Jun 9, 2023 | The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including... |
| CVE-2023-0831 | MEDIUM | 4.3 | 0.3% | Jun 9, 2023 | The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including... |
| CVE-2023-0729 | MEDIUM | 4.3 | 0.3% | Jun 9, 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.... |
| CVE-2023-0710 | MEDIUM | 5.4 | 0.4% | Jun 9, 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'fname' attr... |
| CVE-2023-0709 | MEDIUM | 5.4 | 0.6% | Jun 9, 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_last_nam... |
| CVE-2023-0708 | MEDIUM | 5.4 | 0.6% | Jun 9, 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf_first_na... |
| CVE-2023-0695 | MEDIUM | 5.4 | 0.4% | Jun 9, 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf' shortco... |
| CVE-2023-0694 | MEDIUM | 4.3 | 0.7% | Jun 9, 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode ... |
| CVE-2023-0693 | MEDIUM | 4.3 | 0.7% | Jun 9, 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_transaction... |
| CVE-2023-0692 | MEDIUM | 4.3 | 0.6% | Jun 9, 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_sta... |
| CVE-2023-0691 | MEDIUM | 4.3 | 0.6% | Jun 9, 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_last_name' ... |
| CVE-2023-0688 | MEDIUM | 6.5 | 0.7% | Jun 9, 2023 | The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' s... |
| CVE-2023-34243 | MEDIUM | 5.3 | 0.5% | Jun 8, 2023 | TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgst... |
| CVE-2023-32751 | MEDIUM | 5.4 | 2.9% | Jun 8, 2023 | Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are genera... |
| CVE-2023-32750 | MEDIUM | 6.5 | 3.8% | Jun 8, 2023 | Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which ... |
| CVE-2023-29401 | MEDIUM | 4.3 | 0.5% | Jun 8, 2023 | The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename ... |
| CVE-2023-34961 | MEDIUM | 6.1 | 0.4% | Jun 8, 2023 | Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/co... |
| CVE-2023-34959 | MEDIUM | 5.3 | 0.6% | Jun 8, 2023 | An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain i... |
| CVE-2023-34958 | MEDIUM | 4.3 | 0.4% | Jun 8, 2023 | Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download docum... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now