2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5821MEDIUM6.5The Thumbnail carousel slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is d...
CVE-2023-5820HIGH8.8The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This...
CVE-2023-5705MEDIUM5.4The VK Filter Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk_filter_searc...
CVE-2023-5570HIGH7.5Improper Protection for Outbound Error Messages and Alert Signals vulnerability in Inohom Home Manager Gateway allows Ac...
CVE-2023-5817MEDIUM5.4The Neon text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's neontext_box shortcode ...
CVE-2023-5774MEDIUM5.4The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in...
CVE-2023-46199MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Triberr plugin <= 4.1.1 versions.
CVE-2023-46194MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <...
CVE-2023-46192MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Internet Marketing Ninjas Internal Link Building plugi...
CVE-2023-46153MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.9 versions.
CVE-2023-46093MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in LionScripts.Com Webmaster Tools plugin <= 2.0 versions...
CVE-2023-46091MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bala Krishna, Sergey Yakovlev Category SEO Meta Tags p...
CVE-2023-44220HIGH7.3SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking...
CVE-2023-44219HIGH7.8A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earli...
CVE-2023-34059HIGH7open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with no...
CVE-2023-34058HIGH7.5VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operat...
CVE-2023-34057HIGH7.8VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest vi...
CVE-2023-5051MEDIUM5.4The CallRail Phone Call Tracking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callrail_for...
CVE-2023-46818HIGH7.2An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by ...
CVE-2023-46816HIGH8.8An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulne...
CVE-2023-46815HIGH8.8An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. An Unrestricted File Upload vulnerability has...
CVE-2023-46504MEDIUM5.4Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a physically proximate attacker to execute a...
CVE-2023-46503MEDIUM6.1Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a remote attacker to execute arbitrary code ...
CVE-2023-45499CRITICAL9.8VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.
CVE-2023-45498CRITICAL9.8VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now