2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-7206 | HIGH | 7.8 | 0.2% | Jan 15, 2024 | In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a u... |
| CVE-2023-6991 | HIGH | 8.8 | 0.7% | Jan 15, 2024 | The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters ... |
| CVE-2023-6941 | MEDIUM | 4.8 | 0.4% | Jan 15, 2024 | The Keap Official Opt-in Forms WordPress plugin through 1.0.11 does not sanitise and escape some of its settings, which ... |
| CVE-2023-6843 | MEDIUM | 4.3 | 0.4% | Jan 15, 2024 | The easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg WordPress p... |
| CVE-2023-6623 | CRITICAL | 9.8 | 50.7% | Jan 15, 2024 | The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local var... |
| CVE-2023-6620 | HIGH | 7.2 | 14.2% | Jan 15, 2024 | The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using... |
| CVE-2023-6163 | MEDIUM | 4.8 | 0.4% | Jan 15, 2024 | The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2023-6066 | MEDIUM | 4.3 | 0.4% | Jan 15, 2024 | The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of i... |
| CVE-2023-6050 | MEDIUM | 6.1 | 0.4% | Jan 15, 2024 | The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generat... |
| CVE-2023-6049 | CRITICAL | 9.8 | 0.9% | Jan 15, 2024 | The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which coul... |
| CVE-2023-6048 | MEDIUM | 6.5 | 0.6% | Jan 15, 2024 | The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like... |
| CVE-2023-6029 | HIGH | 7.5 | 0.2% | Jan 15, 2024 | The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does ... |
| CVE-2023-5905 | HIGH | 8.1 | 0.6% | Jan 15, 2024 | The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of... |
| CVE-2023-50729 | CRITICAL | 9.8 | 0.6% | Jan 15, 2024 | Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnera... |
| CVE-2023-4925 | MEDIUM | 4.8 | 0.4% | Jan 15, 2024 | The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which co... |
| CVE-2023-4818 | HIGH | 7.6 | 0.7% | Jan 15, 2024 | PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and... |
| CVE-2023-42137 | HIGH | 7.8 | 0.5% | Jan 15, 2024 | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command executi... |
| CVE-2023-42136 | HIGH | 7.8 | 0.5% | Jan 15, 2024 | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of ar... |
| CVE-2023-42135 | MEDIUM | 6.8 | 0.6% | Jan 15, 2024 | PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via ... |
| CVE-2023-42134 | MEDIUM | 6.8 | 0.6% | Jan 15, 2024 | PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partitio... |
| CVE-2023-5253 | HIGH | 7.5 | 0.5% | Jan 15, 2024 | A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guar... |
| CVE-2023-4001 | MEDIUM | 6.8 | 0.5% | Jan 15, 2024 | An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the con... |
| CVE-2023-46226 | CRITICAL | 9.8 | 1.9% | Jan 15, 2024 | Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users ar... |
| CVE-2023-6915 | MEDIUM | 5.5 | 0.3% | Jan 15, 2024 | A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attac... |
| CVE-2023-50290 | MEDIUM | 6.5 | 68.7% | Jan 15, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now