2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3105 | HIGH | 8.8 | 2.0% | Jul 12, 2023 | The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and includi... |
| CVE-2023-3093 | MEDIUM | 6.1 | 0.5% | Jul 12, 2023 | The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and ... |
| CVE-2023-3092 | MEDIUM | 6.1 | 0.4% | Jul 12, 2023 | The SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, ... |
| CVE-2023-3088 | MEDIUM | 6.1 | 0.4% | Jul 12, 2023 | The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, ... |
| CVE-2023-3087 | MEDIUM | 6.1 | 0.5% | Jul 12, 2023 | The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to,... |
| CVE-2023-3082 | MEDIUM | 6.1 | 0.4% | Jul 12, 2023 | The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, an... |
| CVE-2023-3081 | MEDIUM | 6.1 | 0.7% | Jul 12, 2023 | The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up ... |
| CVE-2023-3080 | MEDIUM | 6.1 | 0.5% | Jul 12, 2023 | The WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions u... |
| CVE-2023-3023 | HIGH | 7.2 | 0.7% | Jul 12, 2023 | The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versions u... |
| CVE-2023-3011 | HIGH | 8.8 | 0.3% | Jul 12, 2023 | The ARMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.5. T... |
| CVE-2023-2869 | MEDIUM | 4.3 | 0.5% | Jul 12, 2023 | The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing cap... |
| CVE-2023-2562 | MEDIUM | 4.3 | 0.5% | Jul 12, 2023 | The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ... |
| CVE-2023-2561 | MEDIUM | 4.3 | 0.4% | Jul 12, 2023 | The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2023-2517 | MEDIUM | 4.3 | 0.4% | Jul 12, 2023 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions ... |
| CVE-2023-30226 | MEDIUM | 5.5 | 0.3% | Jul 12, 2023 | An issue was discovered in function get_gnu_verneed in rizinorg Rizin prior to 0.5.0 verneed_entry allows attackers to c... |
| CVE-2023-37767 | MEDIUM | 5.5 | 0.3% | Jul 11, 2023 | GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the BM_ParseIndexValueRepla... |
| CVE-2023-37766 | MEDIUM | 5.5 | 0.3% | Jul 11, 2023 | GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_dat... |
| CVE-2023-37765 | MEDIUM | 5.5 | 0.3% | Jul 11, 2023 | GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield fu... |
| CVE-2023-37174 | MEDIUM | 5.5 | 0.3% | Jul 11, 2023 | GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene functio... |
| CVE-2023-3127 | CRITICAL | 9.8 | 0.4% | Jul 11, 2023 | An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator... |
| CVE-2023-24492 | HIGH | 8.8 | 0.8% | Jul 11, 2023 | A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an a... |
| CVE-2023-24491 | HIGH | 7.8 | 0.2% | Jul 11, 2023 | A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow ... |
| CVE-2023-29984 | HIGH | 7.5 | 0.8% | Jul 11, 2023 | Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2... |
| CVE-2023-29406 | MEDIUM | 6.5 | 1.3% | Jul 11, 2023 | The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject ... |
| CVE-2023-23756 | MEDIUM | 6.1 | 0.3% | Jul 11, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneV... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now