2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26777MEDIUM6.1Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execu...
CVE-2023-26776MEDIUM6.1Cross Site Scripting vulnerability found in Monitorr v.1.7.6 allows a remote attacker to execute arbitrary code via the ...
CVE-2023-26775HIGH7.8File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted fil...
CVE-2023-26750CRITICAL9.8SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execu...
CVE-2023-26733HIGH7.8Buffer Overflow vulnerability found in tinyTIFF v.3.0 allows a local attacker to cause a denial of service via the TinyT...
CVE-2023-26437MEDIUM5.3Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue af...
CVE-2023-29000MEDIUM6.5The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior...
CVE-2023-28999MEDIUM6.4Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app ...
CVE-2023-28998MEDIUM6.1The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior...
CVE-2023-28997MEDIUM6.5The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior...
CVE-2023-28848MEDIUM5.4user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in vers...
CVE-2023-26866CRITICAL9.8GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respe...
CVE-2023-25356HIGH8.8CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command....
CVE-2023-25355HIGH8.8CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions. A user who has the ability to run comm...
CVE-2023-25305HIGH7.1PolyMC Launcher <= 1.4.3 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitr...
CVE-2023-25303HIGH7.1ATLauncher <= 3.4.26.0 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrar...
CVE-2023-23977MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin fo...
CVE-2023-23870MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8...
CVE-2023-23878MEDIUM5.4Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAP...
CVE-2023-23821MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcin Pietrzak Interactive Polish Map plugin <= 1.2 v...
CVE-2023-23686MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brett Shumaker Simple Staff List plugin <= 2.2.2...
CVE-2023-23685MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in RadiusTheme Portfolio – WordPress Portfolio plug...
CVE-2023-25942MEDIUM6.5 Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious netw...
CVE-2023-25941HIGH7.8 Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local at...
CVE-2023-25940HIGH7.8 Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now