2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26922CRITICAL9.8SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the...
CVE-2023-24773CRITICAL9.8Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list...
CVE-2023-26261CRITICAL9.8In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the sess...
CVE-2023-26952MEDIUM5.4onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Menu module.
CVE-2023-25395CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 router was discovered to contain a command injection vulnerability via the ou par...
CVE-2023-1270MEDIUM5.4Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.
CVE-2023-26950MEDIUM5.4onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Title parameter u...
CVE-2023-1267CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company Ptte...
CVE-2023-23638CRITICAL9.8A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This ...
CVE-2023-1269CRITICAL9.8Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
CVE-2023-24657MEDIUM6.1phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter...
CVE-2023-0090CRITICAL9.8The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user ...
CVE-2023-0089HIGH8.8 The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to...
CVE-2023-27476HIGH7.5OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards,...
CVE-2023-24780CRITICAL9.8Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns...
CVE-2023-26823Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-0783. Reason: This record is a duplicate of CVE-2023-0...
CVE-2023-1264MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392.
CVE-2023-1263MEDIUM5.3The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and in...
CVE-2023-1236MEDIUM4.3Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the...
CVE-2023-1235MEDIUM6.3Type confusion in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the ren...
CVE-2023-1234MEDIUM4.3Inappropriate implementation in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to ...
CVE-2023-1233MEDIUM4.3Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed an attacker who convi...
CVE-2023-1232MEDIUM4.3Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to ...
CVE-2023-1231MEDIUM4.3Inappropriate implementation in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to...
CVE-2023-1230MEDIUM4.3Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 111.0.5563.64 allowed an attacker w...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now