2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1185HIGH8.8A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of t...
CVE-2023-1184HIGH8.8A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is so...
CVE-2023-0839CRITICAL9.8Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ProMIS Process Co. InSCADA allows Acc...
CVE-2023-22858MEDIUM5.3An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files ...
CVE-2023-22857MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in...
CVE-2023-22856MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in...
CVE-2023-26111HIGH7.5All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directo...
CVE-2023-26108MEDIUM5.3Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Ex...
CVE-2023-26107HIGH7.8All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without saniti...
CVE-2023-26106HIGH7.5All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file.
CVE-2023-25077MEDIUM5.4Cross-site scripting vulnerability in Authentication Key Settings of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p...
CVE-2023-22838MEDIUM5.4Cross-site scripting vulnerability in Product List Screen and Product Detail Screen of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUB...
CVE-2023-22438MEDIUM5.4Cross-site scripting vulnerability in Contents Management of EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 ...
CVE-2023-22432MEDIUM6.1Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirec...
CVE-2023-22424HIGH7.8Use-after-free vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Vers...
CVE-2023-22421HIGH7.8Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ...
CVE-2023-22419HIGH7.8Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ...
CVE-2023-22344CRITICAL9.8Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and e...
CVE-2023-22336CRITICAL9.8Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a...
CVE-2023-22335HIGH7.5Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier...
CVE-2023-27641MEDIUM6.1The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XS...
CVE-2023-27635HIGH7.8debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a cr...
CVE-2023-26510MEDIUM5.7Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsiste...
CVE-2023-0734MEDIUM5.3Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.
CVE-2023-1181MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository icret/easyimages2.0 prior to 2.6.7.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now