2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-23795HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Form Builder plugin <= 1.9.9.0 versions.
CVE-2023-20895CRITICAL9.8The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A mal...
CVE-2023-20894CRITICAL9.8The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A ...
CVE-2023-20893CRITICAL9.8The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malici...
CVE-2023-20892CRITICAL9.8The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation...
CVE-2023-35090MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin ...
CVE-2023-34601CRITICAL9.8Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable}...
CVE-2023-33387MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0...
CVE-2023-31213MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WPBakery Page Builder plugin <= 6.13.0 versions.
CVE-2023-29931CRITICAL9.8laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.
CVE-2023-29709HIGH7.5An issue was discovered in /cgi-bin/login_rj.cgi in Wildix WSG24POE version 103SP7D190822, allows attackers to bypass au...
CVE-2023-29708HIGH7.5An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory...
CVE-2023-29707MEDIUM4.8Cross Site Scripting (XSS) vulnerability in GBCOM LAC WEB Control Center version lac-1.3.x, allows attackers to create a...
CVE-2023-28695MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Drew Phillips VigilanTor plugin <= 1.3.10 versions.
CVE-2023-28534MEDIUM5.4Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Job Portal WP Job Portal – A Complete Job Boar...
CVE-2023-28496MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SMTP2GO – Email Made Easy plugin <= 1.4.2 versions.
CVE-2023-28423MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Prism Tech Studios Modern Footnotes plugin <= 1.4.15 v...
CVE-2023-28171MEDIUM5.4Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Chill Brilliance theme <= 1.3.1 versions.
CVE-2023-28166MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aakif Kadiwala Tags Cloud Manager plugin <= 1.0.0 versions...
CVE-2023-27618MEDIUM4.8Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in AGILELOGIX Store Locator WordPress plugin <= 1.4.9 ve...
CVE-2023-27631MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.05.04 v...
CVE-2023-27629MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions...
CVE-2023-27612MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions...
CVE-2023-27413MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Shazzad Hossain Khan W4 Post List plugin <= 2.4....
CVE-2023-32449HIGH7.8 Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An att...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now