2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0778MEDIUM6.8A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal...
CVE-2023-0494HIGH7.8A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be ex...
CVE-2023-0241MEDIUM6.5pgAdmin 4 versions prior to v6.19 contains a directory traversal vulnerability. A user of the product may change another...
CVE-2023-28655MEDIUM5.4A malicious user could leverage this vulnerability to escalate privileges or perform unauthorized actions in the context...
CVE-2023-28652MEDIUM6.5An authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition.
CVE-2023-28650MEDIUM6.1An unauthenticated remote attacker could provide a malicious link and trick an unsuspecting user into clicking on it. If...
CVE-2023-27927MEDIUM6.5An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, des...
CVE-2023-25818HIGH7.1Nextcloud server is an open source, personal cloud implementation. In affected versions a malicious user could try to re...
CVE-2023-25661MEDIUM6.5TensorFlow is an Open Source Machine Learning Framework. In versions prior to 2.11.1 a malicious invalid input crashes a...
CVE-2023-22300MEDIUM6.1An unauthenticated remote attacker could force all authenticated users, such as administrative users, to perform unautho...
CVE-2023-27245MEDIUM6.1A cross-site scripting (XSS) vulnerability in File Management Project 1.0.0 allows attackers to execute arbitrary web sc...
CVE-2023-27241MEDIUM6.1SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the la...
CVE-2023-25828HIGH7.2 Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albu...
CVE-2023-27847CRITICAL9.8SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges vi...
CVE-2023-1654HIGH7.8Denial of Service in GitHub repository gpac/gpac prior to 2.4.0.
CVE-2023-1400MEDIUM4.8The Modern Events Calendar Lite WordPress plugin before 6.5.2 does not sanitise and escape some of its settings, which c...
CVE-2023-1399CRITICAL9.8 N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious ...
CVE-2023-1093MEDIUM6.5The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (Id...
CVE-2023-1092MEDIUM6.5The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4...
CVE-2023-1089MEDIUM4.3The Coupon Zen WordPress plugin before 1.0.6 does not have CSRF check when activating plugins, which could allow attacke...
CVE-2023-1088MEDIUM4.3The WP Plugin Manager WordPress plugin before 1.1.8 does not have CSRF check when activating plugins, which could allow ...
CVE-2023-1087MEDIUM4.3The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could al...
CVE-2023-1086MEDIUM4.3The Preview Link Generator WordPress plugin before 1.0.4 does not have CSRF check when activating plugins, which could a...
CVE-2023-1069MEDIUM5.4The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape ...
CVE-2023-1025MEDIUM4.8The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now