2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29007HIGH7.8Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38...
CVE-2023-24512MEDIUM6.5On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a...
CVE-2023-23839MEDIUM6.5The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allow...
CVE-2023-20872HIGH8.8VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
CVE-2023-20871HIGH7.8VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host ...
CVE-2023-28084MEDIUM5.5HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
CVE-2023-25815LOW2.2In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git...
CVE-2023-25652HIGH7.5Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38...
CVE-2023-25461MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in namithjawahar Wp-Insert plugin <= 2.5.0 versions.
CVE-2023-24005MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media Inline Tweet Sharer – Twitter Sharing Plu...
CVE-2023-23995MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tim Reeves & David Stöckl TinyMCE Custom Styles plugin...
CVE-2023-23889MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25...
CVE-2023-23866MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Carlos Moreira Interactive Geo Maps plugin <= 1....
CVE-2023-23710MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discor...
CVE-2023-30839HIGH8.8PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vul...
CVE-2023-30838CRITICAL9.9PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, the `ValidateCore::isClean...
CVE-2023-2282MEDIUM6.5Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows...
CVE-2023-28090MEDIUM5.5An HPE OneView appliance dump may expose SNMPv3 read credentials
CVE-2023-28089HIGH7.1An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules
CVE-2023-28088HIGH7.8An HPE OneView appliance dump may expose SAN switch administrative credentials
CVE-2023-28087MEDIUM5.5An HPE OneView appliance dump may expose OneView user accounts
CVE-2023-28086MEDIUM5.5An HPE OneView appliance dump may expose proxy credential settings
CVE-2023-25793MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in George Pattihis Link Juice Keeper plugin <= 2.0.2 vers...
CVE-2023-25485MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bernhard Kux JSON Content Importer plugin <= 1.3.15 ve...
CVE-2023-30545MEDIUM6.5PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now