2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-24205CRITICAL9.8Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via ...
CVE-2023-0755CRITICAL9.8 The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash t...
CVE-2023-0754CRITICAL9.8 The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the ...
CVE-2023-26326CRITICAL9.8The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization...
CVE-2023-26325HIGH8.8The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerabili...
CVE-2023-24317HIGH8.1Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_or...
CVE-2023-23920MEDIUM4.2An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an ...
CVE-2023-23919HIGH7.5A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not cl...
CVE-2023-23918HIGH7.5A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to...
CVE-2023-23917HIGH8.8A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the ...
CVE-2023-23916MEDIUM6.5An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTT...
CVE-2023-23915MEDIUM6.5A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functional...
CVE-2023-23914CRITICAL9.1A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functional...
CVE-2023-20089MEDIUM6.5A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Appli...
CVE-2023-20050HIGH7.8A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com...
CVE-2023-20016MEDIUM6.5A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export featur...
CVE-2023-20015MEDIUM6.7A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200,...
CVE-2023-20012MEDIUM4.6A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used i...
CVE-2023-20011HIGH8.8A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and C...
CVE-2023-0597MEDIUM5.5A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the ...
CVE-2023-0044MEDIUM6.1If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated...
CVE-2023-22476MEDIUM4.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions prior to 2.25.6, due to insufficient access-l...
CVE-2023-24415HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions.
CVE-2023-24104CRITICAL9.8Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.
CVE-2023-0988HIGH8.8A vulnerability, which was classified as problematic, has been found in SourceCodester Online Pizza Ordering System 1.0....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now