2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-20073CRITICAL9.8A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Rou...
CVE-2023-20068MEDIUM6.1A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could allow an unauthentica...
CVE-2023-20030MEDIUM6A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2023-20023MEDIUM6.7Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, loc...
CVE-2023-20022MEDIUM6.7Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, loc...
CVE-2023-1788CRITICAL9.8Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.
CVE-2023-1758MEDIUM5.4Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository thorsten/ph...
CVE-2023-1757MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVE-2023-1756MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
CVE-2023-1412HIGH7.8An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for ...
CVE-2023-28632HIGH8.1GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0....
CVE-2023-20021MEDIUM6.7Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, loc...
CVE-2023-26857HIGH7.2An arbitrary file upload vulnerability in /admin/ajax.php?action=save_uploads of Dynamic Transaction Queuing System v1.0...
CVE-2023-26856HIGH7.2Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter a...
CVE-2023-25330CRITICAL9.8A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2023-1871MEDIUM4.3The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4...
CVE-2023-1870MEDIUM4.3The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4...
CVE-2023-1869MEDIUM4.8The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to,...
CVE-2023-1868MEDIUM5.3The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when c...
CVE-2023-1867MEDIUM4.3The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4...
CVE-2023-1866MEDIUM4.3The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4...
CVE-2023-1865MEDIUM6.5The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when ...
CVE-2023-26789MEDIUM6.1Veritas NetBackUp OpsCenter Version 9.1.0.1 is vulnerable to Reflected Cross-site scripting (XSS). The Web App fails to ...
CVE-2023-1860MEDIUM6.1A vulnerability was found in Keysight IXIA Hawkeye 3.3.16.28. It has been declared as problematic. This vulnerability af...
CVE-2023-1858HIGH7.5A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now