2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3222HIGH7.5Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which co...
CVE-2023-3221MEDIUM5.3User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacke...
CVE-2023-4587MEDIUM5.5An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local ...
CVE-2023-4298MEDIUM4.8The 123.chat WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2023-4284MEDIUM6.1The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back ...
CVE-2023-4279HIGH7.5This User Activity Log WordPress plugin before 1.6.7 retrieves client IP addresses from potentially untrusted headers, a...
CVE-2023-4269MEDIUM4.3The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowin...
CVE-2023-4254MEDIUM4.8The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high p...
CVE-2023-4253MEDIUM4.8The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high p...
CVE-2023-4216LOW2.7The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing...
CVE-2023-4151MEDIUM6.1The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back...
CVE-2023-4059MEDIUM4.3The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allow...
CVE-2023-4019HIGH8.8The Media from FTP WordPress plugin before 11.17 does not properly limit who can use the plugin, which may allow users w...
CVE-2023-40214MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vathemes Business Pro theme <= 1.10.4 versions.
CVE-2023-40205MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pixelgrade PixTypes plugin <= 1.4.15 versions.
CVE-2023-40197MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Devaldi Ltd flowpaper plugin <= 1.9.9 versions.
CVE-2023-40196MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <...
CVE-2023-3814MEDIUM4.9The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installatio...
CVE-2023-3499MEDIUM4.8The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.16 does not sanitise and escape some ...
CVE-2023-32578MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Twinpictures Column-Matic plugin <= 1.3.3 versio...
CVE-2023-32296MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kangu para WooCommerce plugin <= 2.2.9 versions.
CVE-2023-32102MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Pexle Chris Library Viewer plugin <= 2.0.6 versi...
CVE-2023-30485MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Solwin Infotech Responsive WordPress Slider – Avartan Slid...
CVE-2023-2813MEDIUM6.1All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1...
CVE-2023-4616HIGH7.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assista...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now