2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-36000MEDIUM6.5A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables ...
CVE-2023-35998MEDIUM4.6A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on ...
CVE-2023-2818MEDIUM5.5An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to...
CVE-2023-2996HIGH8.8The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above t...
CVE-2023-2877HIGH8.8The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in ...
CVE-2023-2842HIGH8.1The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make...
CVE-2023-2795MEDIUM4.8The CodeColorer WordPress plugin before 0.10.1 does not sanitise and escape some of its settings, which could allow high...
CVE-2023-2744HIGH7.2The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/account...
CVE-2023-2743MEDIUM6.1The ERP WordPress plugin before 1.12.4 does not sanitise and escape the employee_name parameter before outputting it bac...
CVE-2023-2711MEDIUM4.8The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which coul...
CVE-2023-2628HIGH8.8The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJ...
CVE-2023-2627MEDIUM4.3The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, a...
CVE-2023-2624MEDIUM6.1The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2023-2623MEDIUM6.5The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user...
CVE-2023-2605MEDIUM6.1The wpbrutalai WordPress plugin before 2.0.1 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2023-2601CRITICAL9.8The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL ...
CVE-2023-2592HIGH7.2The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL s...
CVE-2023-2580MEDIUM4.8The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-p...
CVE-2023-2482HIGH7.2The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it...
CVE-2023-2326MEDIUM6.5The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugi...
CVE-2023-2178MEDIUM4.8The Aajoda Testimonials WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could all...
CVE-2023-2068CRITICAL9.8The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disa...
CVE-2023-2032CRITICAL9.8The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Inj...
CVE-2023-1891MEDIUM6.1The Accordion & FAQ WordPress plugin before 1.9.9 does not escape various generated URLs, before outputting them in attr...
CVE-2023-1166MEDIUM4.8The USM-Premium WordPress plugin before 16.3 does not sanitize and escape some of its settings, which could allow high-p...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now