2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-51989Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-51987. Reason: This candidate is a reservation d...
CVE-2023-51987CRITICAL9.8D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator...
CVE-2023-51984CRITICAL9.8D-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. allows remote attack...
CVE-2023-6938MEDIUM5.4The Oxygen Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom field in all versions ...
CVE-2023-6244MEDIUM4.3The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2023-6242MEDIUM4.3The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2023-51751MEDIUM6.8ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10...
CVE-2023-51750MEDIUM4.6ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the ven...
CVE-2023-51749HIGH8.8ScaleFusion 10.5.2 does not properly limit users to the Edge application because a search can be made from a tooltip. NO...
CVE-2023-51748HIGH8.8ScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is ...
CVE-2023-50159HIGH8.8In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrar...
CVE-2023-20573LOW3.2A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not rec...
CVE-2023-7071MEDIUM5.4The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ...
CVE-2023-7070MEDIUM5.4The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2023-7048MEDIUM4.3The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2023-7019MEDIUM4.3The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthoriz...
CVE-2023-6994MEDIUM6.4The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho...
CVE-2023-6990MEDIUM5.4The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions ...
CVE-2023-6988MEDIUM5.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's extend_build...
CVE-2023-6979HIGH8.8The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty...
CVE-2023-6934MEDIUM5.4The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sho...
CVE-2023-6924MEDIUM4.8The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up ...
CVE-2023-6882MEDIUM6.1The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ pa...
CVE-2023-6878MEDIUM6.5The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2023-6875CRITICAL9.8The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now