2023 CVE Vulnerabilities
31,400 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-4968 | MEDIUM | 4.8 | 0.4% | Oct 20, 2023 | The WPLegalPages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wplegalpage' shortcode in versio... |
| CVE-2023-4947 | MEDIUM | 4.3 | 0.4% | Oct 20, 2023 | The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2023-4943 | MEDIUM | 4.3 | 0.5% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to ... |
| CVE-2023-4942 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4940 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4937 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4935 | MEDIUM | 4.3 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4920 | HIGH | 8.8 | 0.3% | Oct 20, 2023 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du... |
| CVE-2023-4919 | MEDIUM | 5.4 | 0.5% | Oct 20, 2023 | The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `iframe` shortcode in versions up t... |
| CVE-2023-4598 | MEDIUM | 6.5 | 0.9% | Oct 20, 2023 | The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,... |
| CVE-2023-4488 | CRITICAL | 9.8 | 1.0% | Oct 20, 2023 | The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via... |
| CVE-2023-4482 | MEDIUM | 5.4 | 0.3% | Oct 20, 2023 | The Auto Amazon Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in versi... |
| CVE-2023-4402 | CRITICAL | 9.8 | 1.3% | Oct 20, 2023 | The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 ... |
| CVE-2023-4274 | MEDIUM | 6.5 | 1.2% | Oct 20, 2023 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, an... |
| CVE-2023-4271 | MEDIUM | 4.8 | 0.4% | Oct 20, 2023 | The Photospace Responsive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘psres_button_size’ ... |
| CVE-2023-39680 | CRITICAL | 9.8 | 0.6% | Oct 20, 2023 | Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute ar... |
| CVE-2023-2325 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS S... |
| CVE-2023-40361 | HIGH | 7.8 | 0.3% | Oct 20, 2023 | SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker ... |
| CVE-2023-5668 | MEDIUM | 5.4 | 0.3% | Oct 20, 2023 | The WhatsApp Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'whatsapp' ... |
| CVE-2023-5614 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list... |
| CVE-2023-5613 | MEDIUM | 5.4 | 0.4% | Oct 20, 2023 | The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpsscode' sho... |
| CVE-2023-46277 | HIGH | 7.8 | 0.3% | Oct 20, 2023 | please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOC... |
| CVE-2023-34052 | HIGH | 7.8 | 0.2% | Oct 20, 2023 | VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative acce... |
| CVE-2023-34051 | CRITICAL | 9.8 | 44.7% | Oct 20, 2023 | VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can... |
| CVE-2023-46267 | — | — | — | Oct 20, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-5631. Reason: This candidate is a duplicate of C... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now