2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1410MEDIUM4.8Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Gra...
CVE-2023-1051MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in As Koc Energy Web ...
CVE-2023-1050CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web ...
CVE-2023-26114CRITICAL9.3Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. ...
CVE-2023-28759HIGH7.8An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the...
CVE-2023-28758HIGH7.1An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path...
CVE-2023-27249MEDIUM5.5swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.
CVE-2023-26496CRITICAL9.8An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1...
CVE-2023-24367Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2023-23192HIGH7.2IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task.
CVE-2023-28470MEDIUM5.3In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
CVE-2023-26498CRITICAL9.8An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1...
CVE-2023-26088HIGH7.8In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the loc...
CVE-2023-24655CRITICAL9.8Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name...
CVE-2023-27100CRITICAL9.8Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22...
CVE-2023-27060CRITICAL9.8LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.
CVE-2023-27054MEDIUM6.1A cross-site scripting (XSS) vulnerability in MiroTalk P2P before commit f535b35 allows attackers to execute arbitrary w...
CVE-2023-28667CRITICAL9.8The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue....
CVE-2023-28666MEDIUM5.4The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability ...
CVE-2023-28665MEDIUM5.4The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnera...
CVE-2023-28664MEDIUM5.4The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripti...
CVE-2023-28663HIGH8.8The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in ...
CVE-2023-28662CRITICAL9.8The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL in...
CVE-2023-28661HIGH8.8The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in ...
CVE-2023-28660HIGH8.8The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now