2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-51989 | — | — | — | Jan 11, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-51987. Reason: This candidate is a reservation d... |
| CVE-2023-51987 | CRITICAL | 9.8 | 0.9% | Jan 11, 2024 | D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator... |
| CVE-2023-51984 | CRITICAL | 9.8 | 2.0% | Jan 11, 2024 | D-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. allows remote attack... |
| CVE-2023-6938 | MEDIUM | 5.4 | 0.3% | Jan 11, 2024 | The Oxygen Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom field in all versions ... |
| CVE-2023-6244 | MEDIUM | 4.3 | 0.3% | Jan 11, 2024 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2023-6242 | MEDIUM | 4.3 | 0.3% | Jan 11, 2024 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2023-51751 | MEDIUM | 6.8 | 0.2% | Jan 11, 2024 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10... |
| CVE-2023-51750 | MEDIUM | 4.6 | 0.3% | Jan 11, 2024 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the ven... |
| CVE-2023-51749 | HIGH | 8.8 | 0.3% | Jan 11, 2024 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because a search can be made from a tooltip. NO... |
| CVE-2023-51748 | HIGH | 8.8 | 0.3% | Jan 11, 2024 | ScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is ... |
| CVE-2023-50159 | HIGH | 8.8 | 0.3% | Jan 11, 2024 | In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrar... |
| CVE-2023-20573 | LOW | 3.2 | 0.3% | Jan 11, 2024 | A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not rec... |
| CVE-2023-7071 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ... |
| CVE-2023-7070 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2023-7048 | MEDIUM | 4.3 | 0.2% | Jan 11, 2024 | The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2023-7019 | MEDIUM | 4.3 | 0.3% | Jan 11, 2024 | The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2023-6994 | MEDIUM | 6.4 | 0.4% | Jan 11, 2024 | The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho... |
| CVE-2023-6990 | MEDIUM | 5.4 | 0.3% | Jan 11, 2024 | The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions ... |
| CVE-2023-6988 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_build... |
| CVE-2023-6979 | HIGH | 8.8 | 1.1% | Jan 11, 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty... |
| CVE-2023-6934 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho... |
| CVE-2023-6924 | MEDIUM | 4.8 | 0.5% | Jan 11, 2024 | The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up ... |
| CVE-2023-6882 | MEDIUM | 6.1 | 0.4% | Jan 11, 2024 | The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ pa... |
| CVE-2023-6878 | MEDIUM | 6.5 | 0.5% | Jan 11, 2024 | The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ... |
| CVE-2023-6875 | CRITICAL | 9.8 | 90.3% | Jan 11, 2024 | The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress i... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now