2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2889CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veon Computer Serv...
CVE-2023-28747HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in codeboxr CBX Currency Converter plugin <= 3.0.3 versions.
CVE-2023-27633HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Customify – Intuitive Website Styling plugin <= 2.10.4 ver...
CVE-2023-27461HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Yoohoo Plugins When Last Login plugin <= 1.2.1 versions.
CVE-2023-27458HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream plugin <= 4.4.10 versions.
CVE-2023-27457HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Passionate Brains Add Expires Headers & Optimized Minify plugin <= 2....
CVE-2023-27453HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.3.1 versions.
CVE-2023-27451HIGH8.8Server-Side Request Forgery (SSRF) vulnerability in Darren Cooney Instant Images plugin <= 5.1.0.2 versions.
CVE-2023-27446HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Fluenx DeepL API translation plugin <= 2.1.4 versions.
CVE-2023-27444HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Pierre Lannoy / PerfOps One DecaLog plugin <= 3.7.0 versions.
CVE-2023-27442HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.29.2 versions.
CVE-2023-26535HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WPPOOL Sheets To WP Table Live Sync plugin <= 2.12.15 versions.
CVE-2023-26532HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes Social Auto Poster plugin <= 2.1.4 versions.
CVE-2023-43081LOW3.3 PowerProtect Agent for File System Version 19.14 and prior, contains an incorrect default permissions vulnerability in ...
CVE-2023-28749HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3....
CVE-2023-6253MEDIUM6A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to re...
CVE-2023-5983HIGH7.5Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Botanik Software Pharmacy Automation ...
CVE-2023-5047CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DRD Fleet Leasing ...
CVE-2023-3104HIGH7.5Lack of authentication vulnerability. An unauthenticated local user is able to see through the cameras using the web ser...
CVE-2023-3103MEDIUM5.9Authentication bypass vulnerability, the exploitation of which could allow a local attacker to perform a Man-in-the-Midd...
CVE-2023-6189MEDIUM5.3Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and...
CVE-2023-6117HIGH7.5A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API me...
CVE-2023-46673HIGH7.5It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch...
CVE-2023-37924CRITICAL9.8Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can resul...
CVE-2023-6011MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DECE Software Geod...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now