2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28659HIGH8.8The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vuln...
CVE-2023-28439MEDIUM6.1CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been disc...
CVE-2023-28438HIGH8Pimcore is an open source data and experience management platform. Prior to version 10.5.19, since a user with 'report' ...
CVE-2023-28434HIGH8.8Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requ...
CVE-2023-28433HIGH8.8Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are ...
CVE-2023-28432HIGH7.5Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and ...
CVE-2023-28431HIGH7.5Frontier is an Ethereum compatibility layer for Substrate. Frontier's `modexp` precompile uses `num-bigint` crate under ...
CVE-2023-0386HIGH7.8A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa...
CVE-2023-28119HIGH7.5The crewjam/saml go library contains a partial implementation of the SAML standard in golang. Prior to version 0.4.13, t...
CVE-2023-28117MEDIUM6.5Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration ...
CVE-2023-27224CRITICAL9.8An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the config...
CVE-2023-28114MEDIUM4.1`cilium-cli` is the command line interface to install, manage, and troubleshoot Kubernetes clusters running Cilium. Prio...
CVE-2023-25820HIGH7.8Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Enterpris...
CVE-2023-0870MEDIUM6.7A form can be manipulated with cross-site request forgery in multiple versions of OpenNMS Meridian and Horizon. This can...
CVE-2023-27754MEDIUM5.5vox2mesh 1.0 has stack-overflow in main.cpp, this is stack-overflow caused by incorrect use of memcpy() funciton. The fl...
CVE-2023-26426HIGH7.8Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by a Use After Free vulnerability that co...
CVE-2023-26358HIGH7.8Creative Cloud version 5.9.1 (and earlier) is affected by an Untrusted Search Path vulnerability that might allow attack...
CVE-2023-25862MEDIUM5.5Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds read vulnerability th...
CVE-2023-25861HIGH7.8Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds write vulnerability t...
CVE-2023-25860HIGH7.8Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds write vulnerability t...
CVE-2023-25859HIGH7.8Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an Improper Input Validation vulnerabi...
CVE-2023-22271MEDIUM5.3Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for Passwords vulnerability that ...
CVE-2023-22269MEDIUM5.4Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability....
CVE-2023-22266MEDIUM5.4Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect')...
CVE-2023-22265MEDIUM5.4Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect')...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now