2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22707MEDIUM5.4Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin...
CVE-2023-1659Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-1655HIGH7.8Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.4.0.
CVE-2023-1145HIGH7.8 Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerabilit...
CVE-2023-1144HIGH8.8Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in ...
CVE-2023-1143HIGH8.8In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could al...
CVE-2023-1142CRITICAL9.8In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve sy...
CVE-2023-1141HIGH8.8Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could ...
CVE-2023-1140CRITICAL9.8Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker ...
CVE-2023-1139HIGH8.8Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targe...
CVE-2023-1138HIGH7.5Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, whi...
CVE-2023-1137HIGH8.8Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user cou...
CVE-2023-1136HIGH7.5In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a vali...
CVE-2023-1135HIGH7.8 In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set in...
CVE-2023-1134HIGH8.8Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which...
CVE-2023-1133CRITICAL9.8Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status se...
CVE-2023-27096MEDIUM6.5Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information vi...
CVE-2023-26959CRITICAL9.8Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.
CVE-2023-26958MEDIUM4.8Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter...
CVE-2023-24094HIGH7.5An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via c...
CVE-2023-28885MEDIUM6.8The MyLink infotainment system (build 2021.3.26) in General Motors Chevrolet Equinox 2021 vehicles allows attackers to c...
CVE-2023-25909CRITICAL9.8HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote a...
CVE-2023-25018MEDIUM5.4RIFARTEK IOT Wall transportation function has insufficient filtering for user input. An authenticated remote attacker wi...
CVE-2023-25017HIGH8.1RIFARTEK IOT Wall has a vulnerability of incorrect authorization. An authenticated remote attacker with general user pri...
CVE-2023-24842MEDIUM5.3HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vul...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now