2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5038HIGH7.5badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacke...
CVE-2023-6198CRITICAL9.3Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows ...
CVE-2023-50029CRITICAL10PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaSh...
CVE-2023-45195MEDIUM5.3Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote...
CVE-2023-45196HIGH7.5Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacke...
CVE-2023-49793MEDIUM6.5CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Z...
CVE-2023-45673CRITICAL9Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected...
CVE-2023-39517MEDIUM5.4Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected ...
CVE-2023-38506MEDIUM5.4Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows pasti...
CVE-2023-37898MEDIUM5.4Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an un...
CVE-2023-38389CRITICAL9.8Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained b...
CVE-2023-45197CRITICAL9.8The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the ro...
CVE-2023-51375HIGH8.8Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3.
CVE-2023-52884MEDIUM4.4In the Linux kernel, the following vulnerability has been resolved: Input: cyapa - add missing input core locking to su...
CVE-2023-3352MEDIUM4.3The Smush plugin for WordPress is vulnerable to unauthorized deletion of the resmush list due to a missing capability ch...
CVE-2023-3353Rejected reason: ** REJECT ** Developer patched two issues with a single patch, so only one CVE is necessary. Please use...
CVE-2023-49113HIGH7.8The Kiuwan Local Analyzer (KLA) Java scanning application contains several hard-coded secrets in plain text format. In ...
CVE-2023-49112MEDIUM6.5Kiuwan provides an API endpoint /saas/rest/v1/info/application to get information about any application, providing on...
CVE-2023-49111MEDIUM6.5For Kiuwan installations with SSO (single sign-on) enabled, an unauthenticated reflected cross-site scripting attack ca...
CVE-2023-49110HIGH7.2When the Kiuwan Local Analyzer uploads the scan results to the Kiuwan SAST web application (either on-premises or cloud...
CVE-2023-52883HIGH7.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix possible null pointer dereference ...
CVE-2023-25646MEDIUM6.4There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attac...
CVE-2023-3204MEDIUM6.5The Materialis theme for WordPress is vulnerable to limited arbitrary options updates in versions up to, and including, ...
CVE-2023-39312HIGH8.8Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.
CVE-2023-38394HIGH8.8Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now