2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-30112HIGH7.5Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection.
CVE-2023-22728MEDIUM4.3Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Pr...
CVE-2023-1387HIGH7.5Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced ...
CVE-2023-29257HIGH7.2IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code exec...
CVE-2023-24796CRITICAL9.8Password vulnerability found in Vinga WR-AC1200 81.102.1.4370 and before allows a remote attacker to execute arbitrary c...
CVE-2023-26286HIGH7.8IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtim...
CVE-2023-2273HIGH7.5Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby uns...
CVE-2023-2294MEDIUM6.1A vulnerability was found in UCMS 1.6.0. It has been classified as problematic. This affects an unknown part of the file...
CVE-2023-30404CRITICAL9.8Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability ...
CVE-2023-30111MEDIUM6.1Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-30106MEDIUM6.1Sourcecodester Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS) via page=about.
CVE-2023-27843CRITICAL9.8SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileg...
CVE-2023-26735HIGH7.5blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability a...
CVE-2023-26560MEDIUM6.5Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports...
CVE-2023-31223MEDIUM5.4Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.
CVE-2023-0045HIGH7.5The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set ...
CVE-2023-30842Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-25313. Reason: This candidate is a reservation d...
CVE-2023-20870MEDIUM6VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing h...
CVE-2023-20869HIGH8.2VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in th...
CVE-2023-30609MEDIUM4.7matrix-react-sdk is a react-based SDK for inserting a Matrix chat/VoIP client into a web page. Prior to version 3.71.0, ...
CVE-2023-30549HIGH7.8Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable throu...
CVE-2023-2293MEDIUM4.8A vulnerability was found in SourceCodester Purchase Order Management System 1.0. It has been classified as problematic....
CVE-2023-2269MEDIUM4.4A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_cl...
CVE-2023-29012HIGH7.8Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts the command in an un...
CVE-2023-29011HIGH7.8Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which implements a SOCKS5 proxy...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now