2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1827CRITICAL9.8A vulnerability has been found in SourceCodester Centralized Covid Vaccination Records System 1.0 and classified as crit...
CVE-2023-1671CRITICAL9.8A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10...
CVE-2023-1826CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. Thi...
CVE-2023-1728CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Ser...
CVE-2023-1768MEDIUM5.3Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk...
CVE-2023-26976HIGH7.5Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_...
CVE-2023-26855HIGH7.5The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed has...
CVE-2023-1579HIGH7.8Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
CVE-2023-0922MEDIUM5.9The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset pass...
CVE-2023-0614MEDIUM6.5The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insuf...
CVE-2023-0225MEDIUM4.3A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged use...
CVE-2023-26916MEDIUM5.3libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at ...
CVE-2023-24724MEDIUM5.4A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Cons...
CVE-2023-1611MEDIUM6.3A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows a...
CVE-2023-29218HIGH7.5The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputat...
CVE-2023-28854HIGH8.8nophp is a PHP web framework. Prior to version 0.0.1, nophp is vulnerable to shell command injection on httpd user. A pa...
CVE-2023-28851MEDIUM5.4Silverstripe Form Capture provides a method to capture simple silverstripe forms and an admin interface for users. Start...
CVE-2023-28850MEDIUM5.4Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspect...
CVE-2023-28837MEDIUM4.9Wagtail is an open source content management system built on Django. Prior to versions 4.1.4 and 4.2.2, a memory exhaust...
CVE-2023-28836MEDIUM5.4Wagtail is an open source content management system built on Django. Starting in version 1.5 and prior to versions 4.1.4...
CVE-2023-28834MEDIUM4.3Nextcloud Server is an open source personal cloud server. Nextcloud Server 24.0.0 until 24.0.6 and 25.0.0 until 25.0.4, ...
CVE-2023-0977MEDIUM6.5 A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote use...
CVE-2023-0975HIGH7.8 A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/...
CVE-2023-1377MEDIUM6.1The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back ...
CVE-2023-1330MEDIUM6.5The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which c...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now