2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-31211 | MEDIUM | 6.5 | 0.5% | Jan 12, 2024 | Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credent... |
| CVE-2023-52339 | MEDIUM | 6.5 | 1.1% | Jan 12, 2024 | In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can occur when reading or writing. It may result in bu... |
| CVE-2023-36842 | MEDIUM | 6.5 | 0.3% | Jan 12, 2024 | An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networ... |
| CVE-2023-7226 | MEDIUM | 6.5 | 0.4% | Jan 11, 2024 | A vulnerability was found in meetyoucrop big-whale 1.1 and classified as critical. Affected by this issue is some unknow... |
| CVE-2023-50129 | MEDIUM | 6.5 | 0.1% | Jan 11, 2024 | Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief ... |
| CVE-2023-50128 | MEDIUM | 5.3 | 0.2% | Jan 11, 2024 | The remote keyless system of the Hozard alarm system (alarmsystemen) v1.0 sends an identical radio frequency signal for ... |
| CVE-2023-50127 | MEDIUM | 5.9 | 0.4% | Jan 11, 2024 | Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionalit... |
| CVE-2023-50126 | MEDIUM | 6.5 | 0.1% | Jan 11, 2024 | Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned ta... |
| CVE-2023-50125 | MEDIUM | 5.9 | 0.4% | Jan 11, 2024 | A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm sys... |
| CVE-2023-50124 | MEDIUM | 6.8 | 0.4% | Jan 11, 2024 | Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface... |
| CVE-2023-6554 | MEDIUM | 6.5 | 0.6% | Jan 11, 2024 | When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it ... |
| CVE-2023-5118 | MEDIUM | 5.4 | 0.3% | Jan 11, 2024 | The application is vulnerable to Stored Cross-Site Scripting (XSS) in the endpoint /sofer/DocumentService.asc/SaveAnnota... |
| CVE-2023-6938 | MEDIUM | 5.4 | 0.3% | Jan 11, 2024 | The Oxygen Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom field in all versions ... |
| CVE-2023-6244 | MEDIUM | 4.3 | 0.3% | Jan 11, 2024 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2023-6242 | MEDIUM | 4.3 | 0.3% | Jan 11, 2024 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2023-51751 | MEDIUM | 6.8 | 0.2% | Jan 11, 2024 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10... |
| CVE-2023-51750 | MEDIUM | 4.6 | 0.3% | Jan 11, 2024 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the ven... |
| CVE-2023-7071 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ... |
| CVE-2023-7070 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2023-7048 | MEDIUM | 4.3 | 0.2% | Jan 11, 2024 | The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2023-7019 | MEDIUM | 4.3 | 0.3% | Jan 11, 2024 | The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2023-6994 | MEDIUM | 6.4 | 0.4% | Jan 11, 2024 | The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho... |
| CVE-2023-6990 | MEDIUM | 5.4 | 0.3% | Jan 11, 2024 | The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions ... |
| CVE-2023-6988 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_build... |
| CVE-2023-6934 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now