2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5211 | MEDIUM | 6.1 | 0.4% | Oct 31, 2023 | The Fattura24 WordPress plugin before 6.2.8 does not sanitize or escape the 'id' parameter before outputting it back in ... |
| CVE-2023-5098 | HIGH | 8.1 | 0.6% | Oct 31, 2023 | The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like s... |
| CVE-2023-4836 | MEDIUM | 4.3 | 0.5% | Oct 31, 2023 | The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and... |
| CVE-2023-4823 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings... |
| CVE-2023-4610 | — | — | — | Oct 31, 2023 | Rejected reason: The SRCU code was added in upstream kernel v6.4-rc1 and removed before v6.4. This bug only existed in d... |
| CVE-2023-4390 | MEDIUM | 4.8 | 0.4% | Oct 31, 2023 | The Popup box WordPress plugin before 3.7.2 does not sanitize and escape some Popup fields, which could allow high-privi... |
| CVE-2023-4251 | MEDIUM | 4.3 | 0.2% | Oct 31, 2023 | The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attacke... |
| CVE-2023-4250 | MEDIUM | 6.1 | 0.4% | Oct 31, 2023 | The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in... |
| CVE-2023-46979 | CRITICAL | 9.8 | 1.5% | Oct 31, 2023 | TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parame... |
| CVE-2023-46978 | HIGH | 7.5 | 0.5% | Oct 31, 2023 | TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WI... |
| CVE-2023-46977 | CRITICAL | 9.8 | 8.7% | Oct 31, 2023 | TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the fu... |
| CVE-2023-46976 | CRITICAL | 9.8 | 1.5% | Oct 31, 2023 | TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFil... |
| CVE-2023-28777 | HIGH | 8.8 | 0.7% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDas... |
| CVE-2023-25047 | HIGH | 7.2 | 0.7% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP... |
| CVE-2023-25045 | HIGH | 7.2 | 0.5% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP... |
| CVE-2023-24000 | CRITICAL | 9.8 | 2.6% | Oct 31, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GamiPress gamipres... |
| CVE-2023-5116 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpul... |
| CVE-2023-5114 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | The idbbee plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idbbee' shortcode in vers... |
| CVE-2023-5099 | HIGH | 8.8 | 0.9% | Oct 31, 2023 | The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in... |
| CVE-2023-5073 | MEDIUM | 5.4 | 0.4% | Oct 31, 2023 | The iframe forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'iframe' shortcode in version... |
| CVE-2023-38994 | HIGH | 7.8 | 0.3% | Oct 31, 2023 | The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaint... |
| CVE-2023-46622 | MEDIUM | 6.1 | 0.3% | Oct 31, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ollybach WPPizza – A Restaurant Plugin plugin <= 3.18.2 ve... |
| CVE-2023-46313 | MEDIUM | 6.1 | 0.4% | Oct 31, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.4 versions. |
| CVE-2023-46312 | MEDIUM | 6.1 | 0.3% | Oct 31, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zaytech Smart Online Order for Clover plugin <= 1.5.4 vers... |
| CVE-2023-40681 | MEDIUM | 4.8 | 0.3% | Oct 31, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11.10 version... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now