2023 CVE Vulnerabilities

31,267 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-0505MEDIUM4.3The Ever Compare WordPress plugin through 1.2.3 does not have CSRF check when activating plugins, which could allow atta...
CVE-2023-0504MEDIUM4.3The HT Politic WordPress plugin before 2.3.8 does not have CSRF check when activating plugins, which could allow attacke...
CVE-2023-0503MEDIUM4.3The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins...
CVE-2023-0502MEDIUM6.5The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers...
CVE-2023-0501MEDIUM6.5The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attac...
CVE-2023-0500MEDIUM6.5The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow att...
CVE-2023-0499MEDIUM4.3The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attacke...
CVE-2023-0498MEDIUM4.3The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attac...
CVE-2023-0497MEDIUM4.3The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attac...
CVE-2023-0496MEDIUM4.3The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers...
CVE-2023-0495MEDIUM4.3The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could ...
CVE-2023-0491MEDIUM5.4The Schedulicity WordPress plugin through 2.21 does not validate and escape some of its shortcode attributes before outp...
CVE-2023-0484MEDIUM4.3The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF...
CVE-2023-0467MEDIUM4.3The WP Dark Mode WordPress plugin before 4.0.8 does not properly sanitize the style parameter in shortcodes before using...
CVE-2023-0395MEDIUM5.4The menu shortcode WordPress plugin through 1.0 does not validate and escape some of its block options before outputting...
CVE-2023-0336MEDIUM6.5The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities whic...
CVE-2023-0335MEDIUM6.5The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with ro...
CVE-2023-0272MEDIUM5.4The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputt...
CVE-2023-22707MEDIUM5.4Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin...
CVE-2023-27096MEDIUM6.5Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information vi...
CVE-2023-26958MEDIUM4.8Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter...
CVE-2023-28885MEDIUM6.8The MyLink infotainment system (build 2021.3.26) in General Motors Chevrolet Equinox 2021 vehicles allows attackers to c...
CVE-2023-25018MEDIUM5.4RIFARTEK IOT Wall transportation function has insufficient filtering for user input. An authenticated remote attacker wi...
CVE-2023-24842MEDIUM5.3HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vul...
CVE-2023-24839MEDIUM6.1HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now