2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27205CRITICAL9.8Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxt...
CVE-2023-27204CRITICAL9.8Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/...
CVE-2023-27203CRITICAL9.8Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/...
CVE-2023-27202CRITICAL9.8Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/...
CVE-2023-26957CRITICAL9.1onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\...
CVE-2023-0223MEDIUM5.3An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting fr...
CVE-2023-1084LOW2.7An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 befor...
CVE-2023-0483LOW3.8An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting fr...
CVE-2023-25814MEDIUM6.5metersphere is an open source continuous testing platform. In versions prior to 2.7.1 a user who has permission to creat...
CVE-2023-25573HIGH7.5metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability...
CVE-2023-1288HIGH7.5 An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker t...
CVE-2023-1287CRITICAL9.8 An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.
CVE-2023-0845MEDIUM6.5Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that cau...
CVE-2023-26209MEDIUM5.3A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and ...
CVE-2023-26208MEDIUM5.3A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x...
CVE-2023-1294CRITICAL9.8A vulnerability was found in SourceCodester File Tracker Manager System 1.0. It has been classified as critical. Affecte...
CVE-2023-1293HIGH8.1A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. This issue aff...
CVE-2023-1292CRITICAL9.8A vulnerability has been found in SourceCodester Sales Tracker Management System 1.0 and classified as critical. This vu...
CVE-2023-1291CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Sales Tracker Management System 1.0. This...
CVE-2023-1290CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Sales Tracker Management System 1.0....
CVE-2023-1286MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.19.
CVE-2023-1251CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. T...
CVE-2023-27986HIGH7.8emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto...
CVE-2023-27985HIGH7.8emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: ...
CVE-2023-26110CRITICAL9.8All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now