2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27479CRITICAL9.9XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver...
CVE-2023-27478MEDIUM6.5libmemcached-awesome is an open source C/C++ client library and tools for the memcached server. `libmemcached` could ret...
CVE-2023-27475HIGH8.8Goutil is a collection of miscellaneous functionality for the go language. In versions prior to 0.6.0 when users use fsu...
CVE-2023-24775CRITICAL9.8Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member...
CVE-2023-25611HIGH7.3A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0...
CVE-2023-25605HIGH7.2A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the admi...
CVE-2023-25230MEDIUM4.9A Server-Side Request Forgery (SSRF) in loonflow r2.0.14 allows attackers to force the application to make arbitrary req...
CVE-2023-25223HIGH7.2CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.
CVE-2023-23776LOW3.1An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiAnalyzer versions 7.2.0 th...
CVE-2023-1257MEDIUM6.8An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain ac...
CVE-2023-27522HIGH7.5HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: ...
CVE-2023-25690CRITICAL9.8Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack....
CVE-2023-26953MEDIUM4.8onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Administrator...
CVE-2023-24781CRITICAL9.8Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member...
CVE-2023-1254MEDIUM5.4A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as pr...
CVE-2023-1253CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Health Center Patient Record Management S...
CVE-2023-26955MEDIUM5.4onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Admin Group modul...
CVE-2023-26954MEDIUM5.4onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Group module...
CVE-2023-1247Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-1245MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1244MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1243MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1242MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1241MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1240MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now