2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41854HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Ltd. WpCentral plugin <= 1.5.7 versions.
CVE-2023-41853HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WP iCal Availability plugin <= 1.0.3 versions.
CVE-2023-41852HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailMunch – Grow your Email List plugin <= 3.1.2 versions.
CVE-2023-41851HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Dotsquares WP Custom Post Template <= 1.0 versions.
CVE-2023-41850HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Morris Bryant, Ruben Sargsyan Outbound Link Manager plugin <= 1.2 ver...
CVE-2023-41730HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions.
CVE-2023-41697HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Nikunj Soni Easy WP Cleaner plugin <= 1.9 versions.
CVE-2023-41694HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Realbig Team Realbig For WordPress plugin <= 1.0.3 versions.
CVE-2023-41684HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Felix Welberg SIS Handball plugin <= 1.0.45 versions.
CVE-2023-5468MEDIUM5.4The Slick Contact Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dcscf-link' shortcode in ...
CVE-2023-5467MEDIUM5.4The GEO my WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to,...
CVE-2023-45208HIGH8.8A command injection in the parsing_xml_stasurvey function inside libcgifunc.so of the D-Link DAP-X1860 repeater 1.00 thr...
CVE-2023-44959HIGH8.8An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arbitrary code as root ...
CVE-2023-44827HIGH8.8An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows ...
CVE-2023-44826MEDIUM5.4Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a cra...
CVE-2023-42189HIGH7.5Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light str...
CVE-2023-42477MEDIUM6.5SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a v...
CVE-2023-42475MEDIUM4.3The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker...
CVE-2023-42474MEDIUM5.4SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The...
CVE-2023-42473MEDIUM5.4S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticat...
CVE-2023-41365MEDIUM4.3SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault me...
CVE-2023-40310HIGH7.5SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted so...
CVE-2023-5471HIGH7.5A vulnerability, which was classified as critical, was found in codeprojects Farmacia 1.0. Affected is an unknown functi...
CVE-2023-44848HIGH8.1An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_template.php component.
CVE-2023-44847HIGH7.2An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now