2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31441 | MEDIUM | 5.5 | 0.3% | Jul 18, 2023 | In NATO Communications and Information Agency anet (aka Advisor Network) through 3.3.0, an attacker can provide a crafte... |
| CVE-2023-24390 | MEDIUM | 4.8 | 0.4% | Jul 18, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WeSecur Security plugin <= 1.2.1 versions. |
| CVE-2023-32965 | MEDIUM | 6.1 | 0.4% | Jul 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin <= 1.8.7 versions. |
| CVE-2023-30906 | HIGH | 7.8 | 0.1% | Jul 18, 2023 | The vulnerability could be locally exploited to allow escalation of privilege. |
| CVE-2023-38326 | — | — | — | Jul 18, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2023-37973 | HIGH | 8.8 | 0.2% | Jul 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in David Pokorny Replace Word plugin <= 2.1 versions. |
| CVE-2023-37892 | HIGH | 8.8 | 0.2% | Jul 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Kemal YAZICI - PluginPress Shortcode IMDB plugin <= 6.0.8 versions. |
| CVE-2023-37889 | HIGH | 8.8 | 0.2% | Jul 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WPAdmin WPAdmin AWS CDN plugin <= 2.0.13 versions. |
| CVE-2023-37387 | HIGH | 8.8 | 0.2% | Jul 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions. |
| CVE-2023-37386 | HIGH | 8.8 | 0.2% | Jul 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Media Library Helper plugin <= 1.2.0 versions. |
| CVE-2023-25036 | HIGH | 8.8 | 0.2% | Jul 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in akhlesh-nagar, a.Ankit Social Media Icons Widget plugin <= 1.6 versio... |
| CVE-2023-23660 | HIGH | 8.8 | 0.8% | Jul 18, 2023 | Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP MainWP Maintenance Extension plugin <= 4.1.1 versions. |
| CVE-2023-3743 | HIGH | 7.5 | 0.6% | Jul 18, 2023 | Ap Page Builder, in versions lower than 1.7.8.2, could allow a remote attacker to send a specially crafted SQL query to ... |
| CVE-2023-25482 | HIGH | 8.8 | 0.3% | Jul 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Mike Martel WP Tiles plugin <= 1.1.2 versions. |
| CVE-2023-25475 | HIGH | 8.8 | 0.3% | Jul 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Vladimir Prelovac Smart YouTube PRO plugin <= 4.3 versions. |
| CVE-2023-25473 | HIGH | 8.8 | 0.2% | Jul 18, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Miro Mannino Flickr Justified Gallery plugin <= 3.5 versions. |
| CVE-2023-2433 | MEDIUM | 5.4 | 0.4% | Jul 18, 2023 | The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to,... |
| CVE-2023-3714 | HIGH | 8.8 | 0.7% | Jul 18, 2023 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2023-3713 | HIGH | 8.8 | 0.6% | Jul 18, 2023 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2023-3709 | MEDIUM | 5.3 | 0.6% | Jul 18, 2023 | The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, a... |
| CVE-2023-3708 | MEDIUM | 6.1 | 0.5% | Jul 18, 2023 | Several themes for WordPress by DeoThemes are vulnerable to Reflected Cross-Site Scripting via breadcrumbs in various ve... |
| CVE-2023-3459 | HIGH | 7.2 | 0.7% | Jul 18, 2023 | The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to... |
| CVE-2023-3403 | MEDIUM | 4.3 | 0.5% | Jul 18, 2023 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2023-38434 | HIGH | 7.5 | 0.9% | Jul 18, 2023 | xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method. |
| CVE-2023-34143 | HIGH | 8.1 | 0.2% | Jul 18, 2023 | Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on Windows, Linux (Device ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now