2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2574HIGH8.8Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the de...
CVE-2023-2573HIGH8.8Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NT...
CVE-2023-28169MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CoreFortress Easy Event calendar plugin <= 1.0 version...
CVE-2023-25452MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Pretty (prettyboymp) CMS Press plugin <= 0.2.3...
CVE-2023-25052MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa Yandex.News Feed by Teplitsa plugin <= 1.12.5...
CVE-2023-25754CRITICAL9.8Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache A...
CVE-2023-25021MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in FareHarbor FareHarbor for WordPress plugin <= 3.6.6 ve...
CVE-2023-23668MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in GiveWP plugin <= 2.25.1 versions.
CVE-2023-29247MEDIUM5.4Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.
CVE-2023-31039CRITICAL9.8Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptio...
CVE-2023-31038HIGH8.8SQL injection in Log4cxx when using the ODBC appender to send log messages to a database.  No fields sent to the databas...
CVE-2023-2534HIGH8.1Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacke...
CVE-2023-2566MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-30018CRITICAL9.8Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=.
CVE-2023-30257HIGH7.8A buffer overflow in the component /proc/ftxxxx-debug of FiiO M6 Build Number v1.0.4 allows attackers to escalate privil...
CVE-2023-30185CRITICAL9.8CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\System...
CVE-2023-29944CRITICAL9.8Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution. The system command reverse-shell can be exe...
CVE-2023-2565MEDIUM6.1A vulnerability has been found in SourceCodester Multi Language Hotel Management Software 1.0 and classified as problema...
CVE-2023-2564CRITICAL10OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.
CVE-2023-32290HIGH7.5The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.
CVE-2023-31047CRITICAL9.8In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one...
CVE-2023-24400MEDIUM5.4Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Hu-manity.Co Cookie Notice & Compliance for GDPR / CCPA...
CVE-2023-25491MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Samuel Marshall JCH Optimize plugin <= 3.2.2 versions.
CVE-2023-2560MEDIUM6.1A vulnerability was found in jja8 NewBingGoGo up to 2023.5.5.2. It has been rated as problematic. This issue affects som...
CVE-2023-26519MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Benfica Publish to Schedule plugin <= 4.5.4 versi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now