2023 CVE Vulnerabilities
31,267 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0505 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The Ever Compare WordPress plugin through 1.2.3 does not have CSRF check when activating plugins, which could allow atta... |
| CVE-2023-0504 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The HT Politic WordPress plugin before 2.3.8 does not have CSRF check when activating plugins, which could allow attacke... |
| CVE-2023-0503 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins... |
| CVE-2023-0502 | MEDIUM | 6.5 | 0.3% | Mar 27, 2023 | The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers... |
| CVE-2023-0501 | MEDIUM | 6.5 | 0.3% | Mar 27, 2023 | The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attac... |
| CVE-2023-0500 | MEDIUM | 6.5 | 0.3% | Mar 27, 2023 | The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow att... |
| CVE-2023-0499 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attacke... |
| CVE-2023-0498 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attac... |
| CVE-2023-0497 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attac... |
| CVE-2023-0496 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers... |
| CVE-2023-0495 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could ... |
| CVE-2023-0491 | MEDIUM | 5.4 | 0.6% | Mar 27, 2023 | The Schedulicity WordPress plugin through 2.21 does not validate and escape some of its shortcode attributes before outp... |
| CVE-2023-0484 | MEDIUM | 4.3 | 0.3% | Mar 27, 2023 | The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF... |
| CVE-2023-0467 | MEDIUM | 4.3 | 0.7% | Mar 27, 2023 | The WP Dark Mode WordPress plugin before 4.0.8 does not properly sanitize the style parameter in shortcodes before using... |
| CVE-2023-0395 | MEDIUM | 5.4 | 0.5% | Mar 27, 2023 | The menu shortcode WordPress plugin through 1.0 does not validate and escape some of its block options before outputting... |
| CVE-2023-0336 | MEDIUM | 6.5 | 1.0% | Mar 27, 2023 | The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities whic... |
| CVE-2023-0335 | MEDIUM | 6.5 | 1.0% | Mar 27, 2023 | The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with ro... |
| CVE-2023-0272 | MEDIUM | 5.4 | 0.5% | Mar 27, 2023 | The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2023-22707 | MEDIUM | 5.4 | 0.4% | Mar 27, 2023 | Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin... |
| CVE-2023-27096 | MEDIUM | 6.5 | 0.6% | Mar 27, 2023 | Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information vi... |
| CVE-2023-26958 | MEDIUM | 4.8 | 0.5% | Mar 27, 2023 | Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter... |
| CVE-2023-28885 | MEDIUM | 6.8 | 0.4% | Mar 27, 2023 | The MyLink infotainment system (build 2021.3.26) in General Motors Chevrolet Equinox 2021 vehicles allows attackers to c... |
| CVE-2023-25018 | MEDIUM | 5.4 | 0.4% | Mar 27, 2023 | RIFARTEK IOT Wall transportation function has insufficient filtering for user input. An authenticated remote attacker wi... |
| CVE-2023-24842 | MEDIUM | 5.3 | 0.6% | Mar 27, 2023 | HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vul... |
| CVE-2023-24839 | MEDIUM | 6.1 | 0.5% | Mar 27, 2023 | HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now