2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29923MEDIUM5.3PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface.
CVE-2023-27777MEDIUM5.4Cross-site scripting (XSS) vulnerability was discovered in Online Jewelry Shop v1.0 that allows attackers to execute arb...
CVE-2023-30463HIGH7.5Altran picoTCP through 1.7.0 allows memory corruption (and subsequent denial of service) because of an integer overflow ...
CVE-2023-29921MEDIUM5.3PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create app interface.
CVE-2023-27776MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /index.php?page=category_list of Online Jewelry Shop v1.0 allows at...
CVE-2023-26599MEDIUM6.1XSS vulnerability in TripleSign in Tripleplay Platform releases prior to Caveman 3.4.0 allows attackers to inject client...
CVE-2023-25760HIGH8.8Incorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify othe...
CVE-2023-25759MEDIUM5.4OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authen...
CVE-2023-22645HIGH8.8An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get...
CVE-2023-0317MEDIUM4.9Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensi...
CVE-2023-2170MEDIUM4.8The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in v...
CVE-2023-2169MEDIUM4.8The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in v...
CVE-2023-2168MEDIUM4.8The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in ver...
CVE-2023-25620MEDIUM6.5 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of servi...
CVE-2023-25619HIGH7.5 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service...
CVE-2023-2137HIGH8.8Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit...
CVE-2023-2136CRITICAL9.6Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the rend...
CVE-2023-2135HIGH7.5Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to en...
CVE-2023-2134HIGH8.8Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to ...
CVE-2023-2133HIGH8.8Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to ...
CVE-2023-30605MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...
CVE-2023-30558MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...
CVE-2023-30557MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...
CVE-2023-30556MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...
CVE-2023-30555MEDIUM6.5Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now