2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2519CRITICAL9.8A vulnerability has been found in Caton CTP Relay Server 1.2.9 and classified as critical. This vulnerability affects un...
CVE-2023-29996HIGH7.5In NanoMQ v0.15.0-0, segment fault with Null Pointer Dereference occurs in the process of decoding subinfo_decode and un...
CVE-2023-29995HIGH7.5In NanoMQ v0.15.0-0, a Heap overflow occurs in copyn_utf8_str function of mqtt_parser.c
CVE-2023-29994HIGH7.5In NanoMQ v0.15.0-0, Heap overflow occurs in read_byte function of mqtt_code.c.
CVE-2023-30619MEDIUM5.4Tuleap Open ALM is a Libre and Open Source tool for end to end traceability of application and system developments. The ...
CVE-2023-29827CRITICAL9.8ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be i...
CVE-2023-26012MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denzel Chia | Phire Design Custom Login Page plugin <=...
CVE-2023-26010MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App plugin <= 11.18 versions.
CVE-2023-24958HIGH8.8A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow a...
CVE-2023-23470MEDIUM6.4IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-de...
CVE-2023-26016MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tauhidul Alam Simple Portfolio Gallery plugin <= 0.1 v...
CVE-2023-25962MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari Accordion – Multiple Accordion or FAQs...
CVE-2023-22651CRITICAL9.9Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic o...
CVE-2023-25934HIGH7.5 DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacke...
CVE-2023-26125HIGH7.3Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an...
CVE-2023-30331CRITICAL9.8An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a...
CVE-2023-30077CRITICAL9.8Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php...
CVE-2023-29842HIGH8.8ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST para...
CVE-2023-31099HIGH8.8Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe serve...
CVE-2023-27568HIGH8.8SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderS...
CVE-2023-27075MEDIUM5.4A cross-site scripting vulnerability (XSS) in the component microbin/src/pasta.rs of Microbin v1.2.0 allows attackers to...
CVE-2023-25438HIGH7.8An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalat...
CVE-2023-2182HIGH8.8An issue has been discovered in GitLab EE affecting all versions starting from 15.10 before 15.10.5, all versions starti...
CVE-2023-27999HIGH7.8An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 thr...
CVE-2023-27993HIGH7.1A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to d...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now