2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40595HIGH8.8In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query tha...
CVE-2023-40594HIGH7.5In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perf...
CVE-2023-40593HIGH7.5In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion mar...
CVE-2023-40592MEDIUM6.1In Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12, an attacker can craft a special web request that can resul...
CVE-2023-20266HIGH7.2A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communica...
CVE-2023-35094MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Julien Berthelot / MPEmbed WP Matterport Shortco...
CVE-2023-35092MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Abhay Yadav Breadcrumb simple plugin <= 1.3 versions.
CVE-2023-34372MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Didier Sampaolo SpamReferrerBlock plugin <= 2.22 versi...
CVE-2023-32294MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Radical Web Design GDPR Cookie Consent Notice Box plug...
CVE-2023-28692MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.3 versions.
CVE-2023-28415MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in XootiX Side Cart Woocommerce (Ajax) plugin <= 2.2 vers...
CVE-2023-27621MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MrDemonWolf Livestream Notice plugin <= 1.2.0 versions...
CVE-2023-25471MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webcodin WCP OpenWeather plugin <= 2.5.0 versions.
CVE-2023-25466MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Mahlamusa Who Hit The Page – Hit Counter plugin <= 1.4.14....
CVE-2023-25453MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ian Sadovy WordPress Tables plugin <= 1.3.9 versions.
CVE-2023-24401MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Davidsword Mobile Call Now & Map Buttons plugin <= 1.5...
CVE-2023-24397MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Reservation.Studio Reservation.Studio widget plugin <=...
CVE-2023-4209MEDIUM4.3The POEditor WordPress plugin before 0.9.8 does not have CSRF checks in various places, which could allow attackers to m...
CVE-2023-4150MEDIUM4.3The User Activity Tracking and Log WordPress plugin before 4.0.9 does not have proper CSRF checks when managing its lice...
CVE-2023-4109MEDIUM4.8The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection secur...
CVE-2023-4036MEDIUM4.3The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public,...
CVE-2023-4035MEDIUM5.4The Simple Blog Card WordPress plugin before 1.31 does not validate and escape some of its shortcode attributes before o...
CVE-2023-4023MEDIUM4.3The All Users Messenger WordPress plugin through 1.24 does not prevent non-administrator users from deleting messages fr...
CVE-2023-4013MEDIUM6.5The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks...
CVE-2023-3992MEDIUM6.1The PostX WordPress plugin before 3.0.6 does not sanitise and escape a parameter before outputting it back in the page, ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now