2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-30944HIGH7.3The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki ...
CVE-2023-30943MEDIUM5.3The vulnerability was found Moodle which exists because the application allows a user to control path of the older to cr...
CVE-2023-30403HIGH7.5An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows ...
CVE-2023-29778CRITICAL9.8GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.
CVE-2023-26546HIGH8.8European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Si...
CVE-2023-26089CRITICAL9.8European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used...
CVE-2023-30861HIGH7.5Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containi...
CVE-2023-29918MEDIUM5.4RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.
CVE-2023-29868MEDIUM6.5Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and custom...
CVE-2023-29867MEDIUM6.5Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information a...
CVE-2023-2479CRITICAL9.8OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4.
CVE-2023-29856CRITICAL9.8D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in sca...
CVE-2023-2477MEDIUM6.1A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability i...
CVE-2023-2476MEDIUM5.4A vulnerability was found in Dromara J2eeFAST up to 2.6.0. It has been classified as problematic. Affected is an unknown...
CVE-2023-2445MEDIUM4.9Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and earlier allows attackers ...
CVE-2023-2475MEDIUM5.4A vulnerability was found in Dromara J2eeFAST up to 2.6.0 and classified as problematic. This issue affects some unknown...
CVE-2023-2474MEDIUM4.3A vulnerability has been found in Rebuild 3.2 and classified as problematic. This vulnerability affects unknown code. Th...
CVE-2023-2473MEDIUM4.3A vulnerability was found in Dreamer CMS up to 4.1.3. It has been declared as problematic. This vulnerability affects th...
CVE-2023-29772MEDIUM5.2A Cross-site scripting (XSS) vulnerability in the System Log/General Log page of the administrator web UI in ASUS RT-AC5...
CVE-2023-23723MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions...
CVE-2023-30869CRITICAL9.8Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue a...
CVE-2023-32007HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option s...
CVE-2023-31207MEDIUM5.5Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause...
CVE-2023-2000MEDIUM5.4Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
CVE-2023-1196HIGH8.8The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now