2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-26014 | HIGH | 8.8 | 0.3% | May 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Minify HTML plugin <= 2.1.7 vulnerability. |
| CVE-2023-26011 | HIGH | 8.8 | 0.3% | May 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Read More Excerpt Link plugin <= 1.6 versions. |
| CVE-2023-33362 | CRITICAL | 9.8 | 9.1% | May 23, 2023 | Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function. |
| CVE-2023-33361 | CRITICAL | 9.8 | 0.9% | May 23, 2023 | Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php. |
| CVE-2023-33359 | MEDIUM | 4.3 | 0.4% | May 23, 2023 | Piwigo 13.6.0 is vulnerable to Cross Site Request Forgery (CSRF) in the "add tags" function. |
| CVE-2023-30440 | HIGH | 7.9 | 0.2% | May 23, 2023 | IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 thro... |
| CVE-2023-25056 | HIGH | 8.8 | 0.3% | May 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in SlickRemix Feed Them Social plugin <= 3.0.2 versions. |
| CVE-2023-23713 | HIGH | 8.8 | 0.3% | May 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Manoj Thulasidas Theme Tweaker plugin <= 5.20 versions. |
| CVE-2023-23705 | HIGH | 8.8 | 0.3% | May 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin WordPress Books Gallery plugin <= 4.4.8 versions. |
| CVE-2023-33338 | CRITICAL | 9.8 | 3.7% | May 23, 2023 | Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter. |
| CVE-2023-2483 | — | — | — | May 23, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-33203. Reason: This candidate is a reservation d... |
| CVE-2023-25707 | HIGH | 8.8 | 0.2% | May 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 ver... |
| CVE-2023-25481 | HIGH | 8.8 | 0.2% | May 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versions. |
| CVE-2023-25472 | HIGH | 8.8 | 0.3% | May 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.3 versions. |
| CVE-2023-23724 | HIGH | 8.8 | 0.3% | May 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions. |
| CVE-2023-23706 | HIGH | 8.8 | 0.3% | May 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twit... |
| CVE-2023-31669 | MEDIUM | 5.5 | 0.3% | May 23, 2023 | WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote ("). |
| CVE-2023-23694 | HIGH | 7.8 | 0.7% | May 23, 2023 | Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local ... |
| CVE-2023-23693 | HIGH | 8.2 | 0.4% | May 23, 2023 | Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utilit... |
| CVE-2023-2845 | HIGH | 8.1 | 0.7% | May 23, 2023 | Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. |
| CVE-2023-2844 | MEDIUM | 4.9 | 0.7% | May 23, 2023 | Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1... |
| CVE-2023-30469 | MEDIUM | 6.1 | 0.4% | May 23, 2023 | Cross-site Scripting vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component) al... |
| CVE-2023-28413 | CRITICAL | 9.8 | 2.0% | May 23, 2023 | Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attac... |
| CVE-2023-28409 | CRITICAL | 9.8 | 1.2% | May 23, 2023 | Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remo... |
| CVE-2023-28408 | CRITICAL | 9.8 | 1.8% | May 23, 2023 | Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now