2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5386 | MEDIUM | 4.3 | 0.4% | Nov 22, 2023 | The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2023-5385 | MEDIUM | 4.3 | 0.4% | Nov 22, 2023 | The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2023-5383 | MEDIUM | 4.3 | 0.2% | Nov 22, 2023 | The Funnelforms Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ... |
| CVE-2023-5382 | MEDIUM | 4.3 | 0.3% | Nov 22, 2023 | The Funnelforms Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ... |
| CVE-2023-5338 | MEDIUM | 5.4 | 0.4% | Nov 22, 2023 | The Theme Blvd Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions u... |
| CVE-2023-5314 | MEDIUM | 4.3 | 0.4% | Nov 22, 2023 | The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capa... |
| CVE-2023-5234 | MEDIUM | 5.4 | 0.5% | Nov 22, 2023 | The Related Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'woo-related'... |
| CVE-2023-5163 | MEDIUM | 5.4 | 0.6% | Nov 22, 2023 | The Weather Atlas Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortcode-weather-atlas'... |
| CVE-2023-5128 | MEDIUM | 5.4 | 0.5% | Nov 22, 2023 | The TCD Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'map' shortcode in versions up... |
| CVE-2023-5096 | MEDIUM | 5.4 | 0.4% | Nov 22, 2023 | The HTML filter and csv-file search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '... |
| CVE-2023-5048 | MEDIUM | 5.4 | 0.4% | Nov 22, 2023 | The WDContactFormBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Contact_Form_Builder... |
| CVE-2023-4726 | MEDIUM | 4.8 | 0.4% | Nov 22, 2023 | The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions ... |
| CVE-2023-4686 | MEDIUM | 4.3 | 0.5% | Nov 22, 2023 | The WP Customer Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and incl... |
| CVE-2023-48705 | MEDIUM | 5.4 | 0.5% | Nov 22, 2023 | Nautobot is a Network Source of Truth and Network Automation Platform built as a web application All users of Nautobot v... |
| CVE-2023-47350 | HIGH | 8.8 | 0.4% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in SwiftyEdit Content Management System prior to v1.2.0, allows remote a... |
| CVE-2023-2841 | HIGH | 7.2 | 0.6% | Nov 22, 2023 | The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id para... |
| CVE-2023-2497 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. Th... |
| CVE-2023-2449 | CRITICAL | 9.8 | 0.9% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. T... |
| CVE-2023-2448 | MEDIUM | 5.3 | 0.9% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '... |
| CVE-2023-2440 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th... |
| CVE-2023-2438 | MEDIUM | 6.1 | 0.2% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. Th... |
| CVE-2023-2437 | HIGH | 8.1 | 6.8% | Nov 22, 2023 | The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is... |
| CVE-2023-47380 | MEDIUM | 6.1 | 0.7% | Nov 22, 2023 | Admidio v4.2.12 and below is vulnerable to Cross Site Scripting (XSS). |
| CVE-2023-26542 | HIGH | 8.8 | 0.3% | Nov 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Exeebit phpinfo() WP plugin <= 4.0 versions. |
| CVE-2023-6252 | HIGH | 7.5 | 0.9% | Nov 22, 2023 | Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter. This vulnerability could a... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now