2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-23143HIGH7.8Buffer overflow vulnerability in function avc_parse_slice in file media_tools/av_parsers.c. GPAC version 2.3-DEV-rev1-g4...
CVE-2023-23024MEDIUM6.1Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index...
CVE-2023-23015MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Kalkun 0.8.0 via username input in file User_model.php.
CVE-2023-23014MEDIUM6.1Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr...
CVE-2023-23012MEDIUM6.1Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary co...
CVE-2023-23010MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c...
CVE-2023-22458MEDIUM5.5Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` comm...
CVE-2023-0101HIGH8.8A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. ...
CVE-2023-23489CRITICAL9.8The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection...
CVE-2023-23488CRITICAL9.8The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit...
CVE-2023-22912MEDIUM5.3An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. Check...
CVE-2023-22910MEDIUM5.4An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There...
CVE-2023-22964CRITICAL9.1Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when L...
CVE-2023-23691HIGH8.8 Dell EMC PV ME5, versions ME5.1.0.0.0 and ME5.1.0.1.0, contains a Client-side desync Vulnerability. An unauthenticated ...
CVE-2023-23596HIGH8.8jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an...
CVE-2023-20058MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticate...
CVE-2023-20057MEDIUM5.3A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could ...
CVE-2023-20047MEDIUM6.5A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devi...
CVE-2023-20045HIGH7.2A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could a...
CVE-2023-20044HIGH7.3A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. ...
CVE-2023-20043MEDIUM6.7A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. ...
CVE-2023-20040MEDIUM5.5A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote...
CVE-2023-20038HIGH8.8A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local a...
CVE-2023-20037MEDIUM5.4A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cro...
CVE-2023-20026HIGH7.2A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320 and RV3...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now