2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0762 | MEDIUM | 4.3 | 0.3% | May 15, 2023 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting d... |
| CVE-2023-0761 | MEDIUM | 4.3 | 0.3% | May 15, 2023 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting S... |
| CVE-2023-0644 | MEDIUM | 6.1 | 0.5% | May 15, 2023 | The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various p... |
| CVE-2023-0520 | MEDIUM | 5.4 | 0.2% | May 15, 2023 | The RapidExpCart WordPress plugin through 1.0 does not sanitize and escape the url parameter in the rapidexpcart endpoin... |
| CVE-2023-0490 | MEDIUM | 5.4 | 0.5% | May 15, 2023 | The f(x) TOC WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2023-0233 | MEDIUM | 5.4 | 0.5% | May 15, 2023 | The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputti... |
| CVE-2023-23688 | MEDIUM | 5.4 | 0.4% | May 15, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions. |
| CVE-2023-23683 | MEDIUM | 4.8 | 0.4% | May 15, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ozan Canakli White Label Branding for Elementor Page B... |
| CVE-2023-23674 | MEDIUM | 4.8 | 0.4% | May 15, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in RVOLA WP Original Media Path plugin <= 2.4.0 versions. |
| CVE-2023-23654 | MEDIUM | 4.8 | 0.4% | May 15, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SparkPost plugin <= 3.2.5 versions. |
| CVE-2023-22717 | MEDIUM | 5.4 | 0.4% | May 15, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in nCrafts FormCraft plugin <= 1.2.6 versions. |
| CVE-2023-22706 | MEDIUM | 6.1 | 0.4% | May 15, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions. |
| CVE-2023-23449 | MEDIUM | 5.3 | 0.8% | May 15, 2023 | Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 112011... |
| CVE-2023-23448 | MEDIUM | 5.3 | 0.8% | May 15, 2023 | Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 110021... |
| CVE-2023-22703 | MEDIUM | 6.1 | 0.4% | May 15, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webcodin WCP Contact Form plugin <= 3.1.0 versions. |
| CVE-2023-22690 | MEDIUM | 4.8 | 0.4% | May 15, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.775 versions. |
| CVE-2023-22684 | MEDIUM | 4.8 | 0.4% | May 15, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Subscribers.Com Subscribers plugin <= 1.5.3 versions. |
| CVE-2023-2692 | MEDIUM | 6.1 | 0.6% | May 14, 2023 | A vulnerability has been found in SourceCodester ICT Laboratory Management System 1.0 and classified as problematic. Aff... |
| CVE-2023-2691 | MEDIUM | 5.4 | 0.6% | May 14, 2023 | A vulnerability, which was classified as problematic, was found in SourceCodester Personnel Property Equipment System 1.... |
| CVE-2023-32303 | MEDIUM | 5.5 | 0.3% | May 12, 2023 | Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information... |
| CVE-2023-2181 | MEDIUM | 6.5 | 0.7% | May 12, 2023 | An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before ... |
| CVE-2023-2088 | MEDIUM | 6.5 | 1.2% | May 12, 2023 | A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally... |
| CVE-2023-20880 | MEDIUM | 6.7 | 0.2% | May 12, 2023 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to th... |
| CVE-2023-20879 | MEDIUM | 6.7 | 0.2% | May 12, 2023 | VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privil... |
| CVE-2023-27863 | MEDIUM | 4.9 | 0.6% | May 12, 2023 | IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB cred... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now