2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-7206HIGH7.8 In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a u...
CVE-2023-6991HIGH8.8The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters ...
CVE-2023-6941MEDIUM4.8The Keap Official Opt-in Forms WordPress plugin through 1.0.11 does not sanitise and escape some of its settings, which ...
CVE-2023-6843MEDIUM4.3The easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg WordPress p...
CVE-2023-6623CRITICAL9.8The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local var...
CVE-2023-6620HIGH7.2The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using...
CVE-2023-6163MEDIUM4.8The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow ...
CVE-2023-6066MEDIUM4.3The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of i...
CVE-2023-6050MEDIUM6.1The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generat...
CVE-2023-6049CRITICAL9.8The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which coul...
CVE-2023-6048MEDIUM6.5The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like...
CVE-2023-6029HIGH7.5The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does ...
CVE-2023-5905HIGH8.1The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of...
CVE-2023-50729CRITICAL9.8Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnera...
CVE-2023-4925MEDIUM4.8The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which co...
CVE-2023-4818HIGH7.6PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and...
CVE-2023-42137HIGH7.8PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command executi...
CVE-2023-42136HIGH7.8PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of ar...
CVE-2023-42135MEDIUM6.8PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via ...
CVE-2023-42134MEDIUM6.8PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partitio...
CVE-2023-5253HIGH7.5A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guar...
CVE-2023-4001MEDIUM6.8An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the con...
CVE-2023-46226CRITICAL9.8Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users ar...
CVE-2023-6915MEDIUM5.5A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attac...
CVE-2023-50290MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now