2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0987MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Online Pizza Ordering System 1.0. This vulnerabili...
CVE-2023-0986CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Sales Tracker Management System 1.0. This affect...
CVE-2023-24384HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions.
CVE-2023-23659HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in MainWP Matomo Extension <= 4.0.4 versions.
CVE-2023-0869MEDIUM6.1Cross-site scripting in outage/list.htm in multiple versions of OpenNMS Meridian and Horizon allows an attacker access t...
CVE-2023-0868MEDIUM6.1Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an atta...
CVE-2023-0867MEDIUM6.1Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS M...
CVE-2023-0815MEDIUM6.5Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon c...
CVE-2023-0982CRITICAL9.8A vulnerability was found in SourceCodester Yoga Class Registration System 1.0. It has been declared as critical. Affect...
CVE-2023-0981CRITICAL9.8A vulnerability was found in SourceCodester Yoga Class Registration System 1.0. It has been classified as critical. Affe...
CVE-2023-0980CRITICAL9.8A vulnerability was found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This issue af...
CVE-2023-25621MEDIUM6.5Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n...
CVE-2023-0939CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Te...
CVE-2023-26462HIGH8.1ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usab...
CVE-2023-26303MEDIUM5.5Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions ...
CVE-2023-26302MEDIUM5.5Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was all...
CVE-2023-0886Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-3411. Reason: This candidate is a reservation du...
CVE-2023-0885Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-0518. Reason: This candidate is a reservation du...
CVE-2023-0884Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-3759. Reason: This candidate is a reservation du...
CVE-2023-24114CRITICAL9.8typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.
CVE-2023-22974HIGH7.5A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controll...
CVE-2023-22973HIGH8.8A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated...
CVE-2023-22972MEDIUM5.4A Reflected Cross-site scripting (XSS) vulnerability in interface/forms/eye_mag/php/eye_mag_functions.php in OpenEMR < 7...
CVE-2023-0104HIGH7.8 The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious pr...
CVE-2023-24812CRITICAL9.8Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible du...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now