2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3105HIGH8.8The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and includi...
CVE-2023-3093MEDIUM6.1The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and ...
CVE-2023-3092MEDIUM6.1The SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, ...
CVE-2023-3088MEDIUM6.1The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, ...
CVE-2023-3087MEDIUM6.1The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to,...
CVE-2023-3082MEDIUM6.1The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, an...
CVE-2023-3081MEDIUM6.1The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up ...
CVE-2023-3080MEDIUM6.1The WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions u...
CVE-2023-3023HIGH7.2The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versions u...
CVE-2023-3011HIGH8.8The ARMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.5. T...
CVE-2023-2869MEDIUM4.3The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing cap...
CVE-2023-2562MEDIUM4.3The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ...
CVE-2023-2561MEDIUM4.3The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2023-2517MEDIUM4.3The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions ...
CVE-2023-30226MEDIUM5.5An issue was discovered in function get_gnu_verneed in rizinorg Rizin prior to 0.5.0 verneed_entry allows attackers to c...
CVE-2023-37767MEDIUM5.5GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the BM_ParseIndexValueRepla...
CVE-2023-37766MEDIUM5.5GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_dat...
CVE-2023-37765MEDIUM5.5GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield fu...
CVE-2023-37174MEDIUM5.5GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene functio...
CVE-2023-3127CRITICAL9.8An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator...
CVE-2023-24492HIGH8.8 A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an a...
CVE-2023-24491HIGH7.8 A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow ...
CVE-2023-29984HIGH7.5Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2...
CVE-2023-29406MEDIUM6.5The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject ...
CVE-2023-23756MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneV...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now