2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-22611HIGH7.5A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information ...
CVE-2023-22610HIGH7.5 A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server...
CVE-2023-24163CRITICAL9.8SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator tem...
CVE-2023-24162CRITICAL9.8Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readOb...
CVE-2023-24829HIGH8.8Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbe...
CVE-2023-0593MEDIUM5.5A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attac...
CVE-2023-0592MEDIUM5.5A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attack...
CVE-2023-0591MEDIUM5.5 ubireader_extract_files is vulnerable to path traversal when run against specifically crafted UBIFS files, allowing the...
CVE-2023-22900CRITICAL9.8Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vu...
CVE-2023-23582CRITICAL9.8 Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior are vulnerable to a heap-based buffer overflow, which could a...
CVE-2023-22389MEDIUM6.5 Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configura...
CVE-2023-24020CRITICAL9.8 Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection, allowing multiple at...
CVE-2023-22315HIGH7.8 Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does...
CVE-2023-0097MEDIUM5.4The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of ...
CVE-2023-0074MEDIUM5.4The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before ...
CVE-2023-0071MEDIUM5.4The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputti...
CVE-2023-0033MEDIUM5.4The PDF Viewer WordPress plugin before 1.0.0 does not validate and escape one of its shortcode attributes, which could a...
CVE-2023-24830HIGH7.5Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench ...
CVE-2023-0512HIGH7.8Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.
CVE-2023-0581MEDIUM5.3The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side valid...
CVE-2023-0266HIGH7A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 i...
CVE-2023-0240HIGH7.8There is a logic error in io_uring's implementation which can be used to trigger a use-after-free vulnerability leading ...
CVE-2023-0474HIGH8.8Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an attacker who convinced a user to install...
CVE-2023-0473HIGH8.8Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially ex...
CVE-2023-0472HIGH8.8Use after free in WebRTC in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now