2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-48387HIGH8.8TAIWAN-CA(TWCA) JCICSecurityTool fails to check the source website and access locations when executing multiple Registr...
CVE-2023-48380HIGH8Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a...
CVE-2023-6827HIGH8.8The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type val...
CVE-2023-6826HIGH7.2The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the '...
CVE-2023-48378HIGH7.5Softnext Mail SQR Expert has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated r...
CVE-2023-48375HIGH8.8SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users ar...
CVE-2023-48373HIGH7.5ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauth...
CVE-2023-6831HIGH8.1Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
CVE-2023-6707HIGH8.8Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap cor...
CVE-2023-6706HIGH8.8Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engag...
CVE-2023-6705HIGH8.8Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap ...
CVE-2023-6704HIGH8.8Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap...
CVE-2023-6703HIGH8.8Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap c...
CVE-2023-6702HIGH8.8Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corr...
CVE-2023-49347HIGH7.8Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or ma...
CVE-2023-49346HIGH7.8Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or ...
CVE-2023-49345HIGH7.8Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or m...
CVE-2023-49344HIGH7.8Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed...
CVE-2023-49343HIGH7.8Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manip...
CVE-2023-49342HIGH7.8Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or m...
CVE-2023-50472HIGH7.5cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.
CVE-2023-50471HIGH7.5cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
CVE-2023-49294HIGH7.5Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1,...
CVE-2023-37457HIGH8.2Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0...
CVE-2023-50017HIGH8.8Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/database/backu...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now