2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0348HIGH7.5Akuvox E11 allows direct SIP calls. No access control is enforced by the SIP servers, which could allow an attacker to c...
CVE-2023-0347MEDIUM5.3The Akuvox E11 Media Access Control (MAC) address, a primary identifier, combined with the Akuvox E11 IP address, could ...
CVE-2023-0346HIGH7.5Akuvox E11 cloud login is performed through an unencrypted HTTP connection. An attacker could gain access to the Akuvox ...
CVE-2023-0345CRITICAL9.8The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. This password canno...
CVE-2023-25803HIGH7.5Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a...
CVE-2023-25802HIGH7.5Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't ...
CVE-2023-25207CRITICAL9.8PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.
CVE-2023-0355HIGH7.5Akuvox E11 uses a hard-coded cryptographic key, which could allow an attacker to decrypt sensitive information.
CVE-2023-27010HIGH7.8Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability all...
CVE-2023-25279CRITICAL9.8OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a cr...
CVE-2023-27580MEDIUM5.9CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementa...
CVE-2023-1378CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0...
CVE-2023-0973MEDIUM5.5 STEPTools v18SP1 ifcmesh library (v18.1) is affected due to a null pointer dereference, which could allow an attacker t...
CVE-2023-25170HIGH8.8PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site reques...
CVE-2023-0844MEDIUM4.8The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-p...
CVE-2023-0772MEDIUM6.5The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some...
CVE-2023-0749MEDIUM6.5The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually...
CVE-2023-0538MEDIUM5.4The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes bef...
CVE-2023-0477HIGH8.8The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any u...
CVE-2023-0219MEDIUM5.4The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored c...
CVE-2023-0172MEDIUM5.4The Juicer WordPress plugin before 1.11 does not validate and escape some of its shortcode attributes before outputting ...
CVE-2023-0073MEDIUM5.4The Client Logo Carousel WordPress plugin through 3.0.0 does not validate and escape some of its shortcode attributes be...
CVE-2023-0066MEDIUM5.4The Companion Sitemap Generator WordPress plugin through 4.5.1.1 does not validate and escape some of its shortcode attr...
CVE-2023-0037CRITICAL9.8The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some paramete...
CVE-2023-27093MEDIUM6.1Cross Site Scripting vulnerability found in My-Blog allows attackers to cause a denial of service via the Post function.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now