2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32573MEDIUM6.5In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerE...
CVE-2023-30777MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced C...
CVE-2023-2619CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System ...
CVE-2023-2618HIGH7.5A vulnerability, which was classified as problematic, has been found in OpenCV wechat_qrcode Module up to 4.7.0. Affecte...
CVE-2023-2617HIGH7.5A vulnerability classified as problematic was found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this vulnera...
CVE-2023-2615MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.
CVE-2023-2614MEDIUM5.4Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.
CVE-2023-27919MEDIUM5.3Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a rem...
CVE-2023-27918MEDIUM6.1Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1....
CVE-2023-27889HIGH8.8Cross-site request forgery (CSRF) vulnerability in LIQUID SPEECH BALLOON versions prior to 1.2 allows a remote unauthent...
CVE-2023-27888MEDIUM5.4Cross-site scripting vulnerability in Joruri Gw Ver 3.2.5 and earlier allows a remote authenticated attacker to inject a...
CVE-2023-27527HIGH7.5Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specia...
CVE-2023-27510HIGH7.5JB Inquiry form contains an exposure of private personal information to an unauthorized actor vulnerability, which may a...
CVE-2023-27385HIGH7.8Heap-based buffer overflow vulnerability exists in CX-Drive All models all versions. By having a user open a specially c...
CVE-2023-25184HIGH7.5Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticat...
CVE-2023-25072HIGH7.5Use of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauth...
CVE-2023-25070MEDIUM6.5Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the ...
CVE-2023-24586MEDIUM6.5Cleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may al...
CVE-2023-23906HIGH7.5Missing authentication for critical function exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may ...
CVE-2023-23901MEDIUM6.5Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and...
CVE-2023-23578HIGH7.5Improper access control vulnerability in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier allows a remote unauthenti...
CVE-2023-22441HIGH8.6Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attack...
CVE-2023-22361MEDIUM6.5Improper privilege management vulnerability in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier allows a remote aut...
CVE-2023-32570MEDIUM5.9VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_d...
CVE-2023-32569CRITICAL9.8An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The Info...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now