2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28642HIGH7.8runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor ca...
CVE-2023-27489MEDIUM5.4Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS accepts SVG files up...
CVE-2023-25809MEDIUM6.3runc is a CLI tool for spawning and running containers according to the OCI specification. In affected versions it was f...
CVE-2023-26984HIGH8.1An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the ...
CVE-2023-27167MEDIUM6.5Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/abs...
CVE-2023-26968CRITICAL9.8In Atrocore 1.5.25, the Create Import Feed option with glyphicon-glyphicon-paperclip function is vulnerable to Unauthent...
CVE-2023-26292MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud S...
CVE-2023-26291MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud S...
CVE-2023-26290MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud S...
CVE-2023-1550MEDIUM5.5Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 ins...
CVE-2023-1704MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20.
CVE-2023-1703MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.
CVE-2023-1702MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.
CVE-2023-1701MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.20.
CVE-2023-28892HIGH7.8Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs...
CVE-2023-26982MEDIUM5.4Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter un...
CVE-2023-1680HIGH7.5A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown...
CVE-2023-1575MEDIUM4.8The Mega Main Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters...
CVE-2023-1663MEDIUM5.3Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthor...
CVE-2023-28158MEDIUM5.4Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploite...
CVE-2023-23861HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in German Mesky GMAce plugin <= 1.5.2 versions.
CVE-2023-1690MEDIUM6.1A vulnerability, which was classified as problematic, has been found in SourceCodester Earnings and Expense Tracker App ...
CVE-2023-1509HIGH8.8The GMAce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This...
CVE-2023-0213HIGH7.8Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges ...
CVE-2023-1689MEDIUM6.1A vulnerability classified as problematic was found in SourceCodester Earnings and Expense Tracker App 1.0. This vulnera...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now