2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-31211MEDIUM6.5Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credent...
CVE-2023-52339MEDIUM6.5In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can occur when reading or writing. It may result in bu...
CVE-2023-36842MEDIUM6.5 An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networ...
CVE-2023-7226MEDIUM6.5A vulnerability was found in meetyoucrop big-whale 1.1 and classified as critical. Affected by this issue is some unknow...
CVE-2023-50129MEDIUM6.5Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief ...
CVE-2023-50128MEDIUM5.3The remote keyless system of the Hozard alarm system (alarmsystemen) v1.0 sends an identical radio frequency signal for ...
CVE-2023-50127MEDIUM5.9Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionalit...
CVE-2023-50126MEDIUM6.5Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned ta...
CVE-2023-50125MEDIUM5.9A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm sys...
CVE-2023-50124MEDIUM6.8Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface...
CVE-2023-6554MEDIUM6.5When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it ...
CVE-2023-5118MEDIUM5.4The application is vulnerable to Stored Cross-Site Scripting (XSS) in the endpoint /sofer/DocumentService.asc/SaveAnnota...
CVE-2023-6938MEDIUM5.4The Oxygen Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom field in all versions ...
CVE-2023-6244MEDIUM4.3The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2023-6242MEDIUM4.3The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2023-51751MEDIUM6.8ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10...
CVE-2023-51750MEDIUM4.6ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the ven...
CVE-2023-7071MEDIUM5.4The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ...
CVE-2023-7070MEDIUM5.4The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2023-7048MEDIUM4.3The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2023-7019MEDIUM4.3The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthoriz...
CVE-2023-6994MEDIUM6.4The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho...
CVE-2023-6990MEDIUM5.4The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions ...
CVE-2023-6988MEDIUM5.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_build...
CVE-2023-6934MEDIUM5.4The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now