2023 CVE Vulnerabilities
31,404 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-28801 | CRITICAL | 9.8 | 0.3% | Aug 31, 2023 | An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privileg... |
| CVE-2023-33833 | LOW | 3.3 | 0.1% | Aug 31, 2023 | IBM Security Verify Information Queue 10.0.4 and 10.0.5 stores sensitive information in plain clear text which can be re... |
| CVE-2023-41741 | HIGH | 7.5 | 0.7% | Aug 31, 2023 | Exposure of sensitive information to an unauthorized actor vulnerability in cgi component in Synology Router Manager (SR... |
| CVE-2023-41740 | MEDIUM | 5.3 | 0.8% | Aug 31, 2023 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synolog... |
| CVE-2023-41739 | MEDIUM | 6.5 | 0.7% | Aug 31, 2023 | Uncontrolled resource consumption vulnerability in File Functionality in Synology Router Manager (SRM) before 1.3.1-9346... |
| CVE-2023-41738 | HIGH | 8.8 | 1.5% | Aug 31, 2023 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Do... |
| CVE-2023-20900 | HIGH | 7.5 | 1.2% | Aug 31, 2023 | A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vspher... |
| CVE-2023-4500 | MEDIUM | 4.8 | 0.3% | Aug 31, 2023 | The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter ... |
| CVE-2023-4471 | MEDIUM | 6.1 | 0.5% | Aug 31, 2023 | The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_d... |
| CVE-2023-4315 | MEDIUM | 6.1 | 0.4% | Aug 31, 2023 | The Woo Custom Emails for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wcemails_edit' parameter in... |
| CVE-2023-4245 | MEDIUM | 4.3 | 0.4% | Aug 31, 2023 | The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capabili... |
| CVE-2023-4161 | MEDIUM | 4.3 | 0.3% | Aug 31, 2023 | The WooCommerce PDF Invoice Builder for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce che... |
| CVE-2023-4160 | MEDIUM | 4.8 | 0.4% | Aug 31, 2023 | The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings... |
| CVE-2023-4000 | MEDIUM | 4.3 | 0.2% | Aug 31, 2023 | The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an... |
| CVE-2023-3999 | MEDIUM | 4.3 | 0.3% | Aug 31, 2023 | The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability c... |
| CVE-2023-3764 | MEDIUM | 4.3 | 0.2% | Aug 31, 2023 | The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, ... |
| CVE-2023-3677 | HIGH | 8.8 | 0.6% | Aug 31, 2023 | The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in vers... |
| CVE-2023-3636 | HIGH | 8.8 | 0.7% | Aug 31, 2023 | The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.... |
| CVE-2023-3404 | MEDIUM | 4.9 | 0.6% | Aug 31, 2023 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, ... |
| CVE-2023-3162 | CRITICAL | 9.8 | 1.0% | Aug 31, 2023 | The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to,... |
| CVE-2023-2354 | MEDIUM | 5.4 | 0.5% | Aug 31, 2023 | The CHP Ads Block Detector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings reachabl... |
| CVE-2023-2353 | MEDIUM | 4.3 | 0.5% | Aug 31, 2023 | The CHP Ads Block Detector plugin for WordPress is vulnerable to unauthorized plugin settings update and reset due to a ... |
| CVE-2023-2352 | MEDIUM | 4.3 | 0.3% | Aug 31, 2023 | The CHP Ads Block Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu... |
| CVE-2023-2279 | MEDIUM | 5.4 | 0.3% | Aug 31, 2023 | The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ... |
| CVE-2023-2229 | HIGH | 8.8 | 0.7% | Aug 31, 2023 | The Quick Post Duplicator for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, an... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now