2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-32960 | MEDIUM | 6.1 | 0.2% | Jun 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <=... |
| CVE-2023-32239 | MEDIUM | 5.4 | 0.4% | Jun 22, 2023 | Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in xtemos WoodMart theme <= 7.2.1 versions. |
| CVE-2023-28774 | MEDIUM | 4.8 | 0.4% | Jun 22, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Grade Us, Inc. Review Stream plugin <= 1.6.5 versions. |
| CVE-2023-28418 | MEDIUM | 5.4 | 0.4% | Jun 22, 2023 | Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Yudlee themes Mediciti Lite theme <= 1.3.0 ver... |
| CVE-2023-25500 | MEDIUM | 4.3 | 0.5% | Jun 22, 2023 | Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24... |
| CVE-2023-25499 | MEDIUM | 6.5 | 0.6% | Jun 22, 2023 | When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.... |
| CVE-2023-20896 | HIGH | 7.5 | 0.9% | Jun 22, 2023 | The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A m... |
| CVE-2023-35918 | MEDIUM | 6.1 | 0.4% | Jun 22, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Bulk Stock Management plugin <= 2.2.33 version... |
| CVE-2023-35917 | HIGH | 8.8 | 0.3% | Jun 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions. |
| CVE-2023-35093 | MEDIUM | 6.5 | 0.6% | Jun 22, 2023 | Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Educatio... |
| CVE-2023-34939 | CRITICAL | 9.8 | 5.0% | Jun 22, 2023 | Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the... |
| CVE-2023-31868 | MEDIUM | 5.4 | 0.4% | Jun 22, 2023 | Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamica... |
| CVE-2023-31867 | HIGH | 7.2 | 0.8% | Jun 22, 2023 | Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection. |
| CVE-2023-30500 | MEDIUM | 6.1 | 0.4% | Jun 22, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (... |
| CVE-2023-29711 | CRITICAL | 9.8 | 70.3% | Jun 22, 2023 | An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitr... |
| CVE-2023-28784 | MEDIUM | 6.1 | 0.4% | Jun 22, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 21.1.2 versions. |
| CVE-2023-28778 | MEDIUM | 4.8 | 0.4% | Jun 22, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Pagination plugin <= 1.2.2 versions. |
| CVE-2023-28776 | MEDIUM | 6.1 | 0.4% | Jun 22, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Continuous Image Carousel With Lig... |
| CVE-2023-28750 | MEDIUM | 6.1 | 0.4% | Jun 22, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On line plugin <= 4.6 versio... |
| CVE-2023-28174 | MEDIUM | 4.8 | 0.4% | Jun 22, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in eLightUp eRocket plugin <= 1.2.4 versions. |
| CVE-2023-27452 | MEDIUM | 4.8 | 0.4% | Jun 22, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow-Company Button Generator – easily Button Builder p... |
| CVE-2023-26539 | MEDIUM | 4.8 | 0.4% | Jun 22, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Chirkov Advanced Text Widget plugin <= 2.1.2 versi... |
| CVE-2023-26534 | MEDIUM | 4.8 | 0.4% | Jun 22, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in OneWebsite WP Repost plugin <= 0.1 versions. |
| CVE-2023-23811 | MEDIUM | 4.8 | 0.4% | Jun 22, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Neil Gee Smoothscroller plugin <= 1.0.0 versions. |
| CVE-2023-23807 | MEDIUM | 4.8 | 0.4% | Jun 22, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Qumos MojoPlug Slide Panel plugin <= 1.1.2 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now