2023 CVE Vulnerabilities

31,400 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4968MEDIUM4.8The WPLegalPages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wplegalpage' shortcode in versio...
CVE-2023-4947MEDIUM4.3The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2023-4943MEDIUM4.3The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ...
CVE-2023-4942MEDIUM4.3The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4940MEDIUM4.3The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4937MEDIUM4.3The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4935MEDIUM4.3The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4920HIGH8.8The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du...
CVE-2023-4919MEDIUM5.4The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `iframe` shortcode in versions up t...
CVE-2023-4598MEDIUM6.5The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,...
CVE-2023-4488CRITICAL9.8The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via...
CVE-2023-4482MEDIUM5.4The Auto Amazon Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in versi...
CVE-2023-4402CRITICAL9.8The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 ...
CVE-2023-4274MEDIUM6.5The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, an...
CVE-2023-4271MEDIUM4.8The Photospace Responsive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘psres_button_size’ ...
CVE-2023-39680CRITICAL9.8Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute ar...
CVE-2023-2325MEDIUM5.4Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS S...
CVE-2023-40361HIGH7.8SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker ...
CVE-2023-5668MEDIUM5.4The WhatsApp Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'whatsapp' ...
CVE-2023-5614MEDIUM5.4The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list...
CVE-2023-5613MEDIUM5.4The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpsscode' sho...
CVE-2023-46277HIGH7.8please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOC...
CVE-2023-34052HIGH7.8VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative acce...
CVE-2023-34051CRITICAL9.8VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can...
CVE-2023-46267Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-5631. Reason: This candidate is a duplicate of C...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now