2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-35818MEDIUM6.8An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker ...
CVE-2023-37968HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Faboba Falang multilanguage for WordPress plugin <= 1.3.39 versions.
CVE-2023-36514HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions.
CVE-2023-36513HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.5 versions.
CVE-2023-36511HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Order Barcodes plugin <= 1.6.4 versions.
CVE-2023-34005HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Front End Users plugin <= 3.2.24 versions.
CVE-2023-31853MEDIUM6.1Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon paramet...
CVE-2023-31851MEDIUM6.1Cudy LT400 1.13.4 is has a cross-site scripting (XSS) vulnerability in /cgi-bin/luci/admin/network/wireless/status via t...
CVE-2023-2958CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in Origin Software ATS Pro allows Authentication Abuse, A...
CVE-2023-3496Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-3418Rejected reason: The issue is not in the plugin itself but the underlying chat service
CVE-2023-3376CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digital Strategy Z...
CVE-2023-3245MEDIUM4.8The Floating Chat Widget WordPress plugin before 3.1.2 does not sanitise and escape some of its settings, which could al...
CVE-2023-3186CRITICAL9.8The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attac...
CVE-2023-3182MEDIUM6.1The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2023-3179HIGH8.8The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could al...
CVE-2023-3041MEDIUM6.1The Autochat Automatic Conversation WordPress plugin through 1.1.7 does not sanitise and escape user input before output...
CVE-2023-35880HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.49 versions.
CVE-2023-35096HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in myCred plugin <= 2.5 versions.
CVE-2023-35089HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipe...
CVE-2023-35038HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in wpexperts.Io WP PDF Generator plugin <= 1.2.2 versions.
CVE-2023-31852MEDIUM6.1Cudy LT400 1.13.4 is vulnerable to Cross Site Scripting (XSS) in cgi-bin/luci/admin/network/wireless/config via the ifac...
CVE-2023-31216HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Ultimate Member plugin <= 2.6.0 versions.
CVE-2023-2963CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oliva Expertise Ol...
CVE-2023-2960MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliva Expertise Ol...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now