2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0542 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode at... |
| CVE-2023-0537 | MEDIUM | 5.4 | 0.5% | May 8, 2023 | The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcod... |
| CVE-2023-0536 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | The Wp-D3 WordPress plugin through 2.4.1 does not validate and escape some of its shortcode attributes before outputting... |
| CVE-2023-0526 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | The Post Shortcode WordPress plugin through 2.0.9 does not validate and escape some of its shortcode attributes before o... |
| CVE-2023-0522 | MEDIUM | 6.5 | 0.3% | May 8, 2023 | The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updati... |
| CVE-2023-0514 | MEDIUM | 6.1 | 0.9% | May 8, 2023 | The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back ... |
| CVE-2023-0421 | MEDIUM | 6.1 | 0.5% | May 8, 2023 | The Cloud Manager WordPress plugin through 1.0 does not sanitise and escape the query param ricerca before outputting it... |
| CVE-2023-0280 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | The Ultimate Carousel For Elementor WordPress plugin through 2.1.7 does not validate and escape some of its block option... |
| CVE-2023-0268 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortco... |
| CVE-2023-0267 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its sh... |
| CVE-2023-28169 | MEDIUM | 4.8 | 0.4% | May 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CoreFortress Easy Event calendar plugin <= 1.0 version... |
| CVE-2023-25452 | MEDIUM | 4.8 | 0.4% | May 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Pretty (prettyboymp) CMS Press plugin <= 0.2.3... |
| CVE-2023-25052 | MEDIUM | 4.8 | 0.4% | May 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa Yandex.News Feed by Teplitsa plugin <= 1.12.5... |
| CVE-2023-25021 | MEDIUM | 4.8 | 0.4% | May 8, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in FareHarbor FareHarbor for WordPress plugin <= 3.6.6 ve... |
| CVE-2023-23668 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in GiveWP plugin <= 2.25.1 versions. |
| CVE-2023-29247 | MEDIUM | 5.4 | 1.9% | May 8, 2023 | Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0. |
| CVE-2023-2566 | MEDIUM | 4.8 | 0.5% | May 8, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1. |
| CVE-2023-2565 | MEDIUM | 6.1 | 0.5% | May 7, 2023 | A vulnerability has been found in SourceCodester Multi Language Hotel Management Software 1.0 and classified as problema... |
| CVE-2023-24400 | MEDIUM | 5.4 | 0.4% | May 7, 2023 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Hu-manity.Co Cookie Notice & Compliance for GDPR / CCPA... |
| CVE-2023-25491 | MEDIUM | 4.8 | 0.4% | May 6, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Samuel Marshall JCH Optimize plugin <= 3.2.2 versions. |
| CVE-2023-2560 | MEDIUM | 6.1 | 0.5% | May 6, 2023 | A vulnerability was found in jja8 NewBingGoGo up to 2023.5.5.2. It has been rated as problematic. This issue affects som... |
| CVE-2023-26519 | MEDIUM | 4.8 | 0.4% | May 6, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Benfica Publish to Schedule plugin <= 4.5.4 versi... |
| CVE-2023-26517 | MEDIUM | 4.8 | 0.4% | May 6, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <= 3.2.1 ver... |
| CVE-2023-24957 | MEDIUM | 5.4 | 0.4% | May 6, 2023 | IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2,... |
| CVE-2023-29354 | MEDIUM | 4.7 | 1.4% | May 5, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now