2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22369Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-25011. Reason: This candidate is a duplicate of ...
CVE-2023-23286MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the s...
CVE-2023-0771HIGH8.8SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.
CVE-2023-24690MEDIUM5.4ChurchCRM 4.5.3 and below was discovered to contain a stored cross-site scripting (XSS) vulnerability at /api/public/reg...
CVE-2023-24686MEDIUM4.8An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importi...
CVE-2023-24685HIGH7.2ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Eve...
CVE-2023-24684HIGH7.2ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the EID parameter at GetText.php.
CVE-2023-23592HIGH7.5WALLIX Access Manager 3.x through 4.0.x allows a remote attacker to access sensitive information.
CVE-2023-0770HIGH7.8Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.
CVE-2023-23631HIGH7.5github.com/ipfs/go-unixfsnode is an ADL IPLD prime node that wraps go-codec-dagpb's implementation of protobuf to enable...
CVE-2023-23626HIGH7.5go-bitfield is a simple bitfield package for the go language aiming to be more performant that the standard library. Whe...
CVE-2023-23625HIGH7.5go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT shar...
CVE-2023-24689MEDIUM4.3An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of...
CVE-2023-24688MEDIUM5.3An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registr...
CVE-2023-24687MEDIUM5.4Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Sett...
CVE-2023-24323HIGH8.8Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.
CVE-2023-24322MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows atta...
CVE-2023-23912HIGH8.8A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.5...
CVE-2023-22799HIGH7.5A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input...
CVE-2023-22798MEDIUM6.1Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interc...
CVE-2023-22797MEDIUM6.1An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling red...
CVE-2023-22796HIGH7.5A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed ...
CVE-2023-22795HIGH7.5A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match heade...
CVE-2023-22794HIGH8.8A vulnerability in ActiveRecord <6.0.6.1, v6.1.7.1 and v7.0.4.1 related to the sanitization of comments. If malicious us...
CVE-2023-22792HIGH7.5A regular expression based DoS vulnerability in Action Dispatch <6.0.6.1,< 6.1.7.1, and <7.0.4.1. Specially crafted cook...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now