2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28801CRITICAL9.8An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privileg...
CVE-2023-33833LOW3.3IBM Security Verify Information Queue 10.0.4 and 10.0.5 stores sensitive information in plain clear text which can be re...
CVE-2023-41741HIGH7.5Exposure of sensitive information to an unauthorized actor vulnerability in cgi component in Synology Router Manager (SR...
CVE-2023-41740MEDIUM5.3Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synolog...
CVE-2023-41739MEDIUM6.5Uncontrolled resource consumption vulnerability in File Functionality in Synology Router Manager (SRM) before 1.3.1-9346...
CVE-2023-41738HIGH8.8Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Do...
CVE-2023-20900HIGH7.5A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vspher...
CVE-2023-4500MEDIUM4.8The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter ...
CVE-2023-4471MEDIUM6.1The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_d...
CVE-2023-4315MEDIUM6.1The Woo Custom Emails for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wcemails_edit' parameter in...
CVE-2023-4245MEDIUM4.3The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capabili...
CVE-2023-4161MEDIUM4.3The WooCommerce PDF Invoice Builder for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce che...
CVE-2023-4160MEDIUM4.8The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings...
CVE-2023-4000MEDIUM4.3The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an...
CVE-2023-3999MEDIUM4.3The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability c...
CVE-2023-3764MEDIUM4.3The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, ...
CVE-2023-3677HIGH8.8The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in vers...
CVE-2023-3636HIGH8.8The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6....
CVE-2023-3404MEDIUM4.9The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, ...
CVE-2023-3162CRITICAL9.8The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to,...
CVE-2023-2354MEDIUM5.4The CHP Ads Block Detector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings reachabl...
CVE-2023-2353MEDIUM4.3The CHP Ads Block Detector plugin for WordPress is vulnerable to unauthorized plugin settings update and reset due to a ...
CVE-2023-2352MEDIUM4.3The CHP Ads Block Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu...
CVE-2023-2279MEDIUM5.4The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ...
CVE-2023-2229HIGH8.8The Quick Post Duplicator for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, an...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now