2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6731MEDIUM4.3The WP Show Posts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on...
CVE-2023-6214HIGH7.5The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all ...
CVE-2023-50685HIGH7.5An issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script t...
CVE-2023-47727MEDIUM4.3IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.20.0 could al...
CVE-2023-37244HIGH7The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows s...
CVE-2023-41971HIGH7.8An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows a...
CVE-2023-41970HIGH7.8An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on Windows during the Repair A...
CVE-2023-28798CRITICAL9.8An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code ex...
CVE-2023-51631MEDIUM6.8D-Link DIR-X3260 prog.cgi SetUsersSettings Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnera...
CVE-2023-46295CRITICAL9.8An issue was discovered in Teledyne FLIR M300 2.00-19. Unauthenticated remote code execution can occur in the web server...
CVE-2023-46294LOW3.4An issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypte...
CVE-2023-26793CRITICAL9.8libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.
CVE-2023-23022MEDIUM6.1Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 employee's payroll management system 1.0, allows at...
CVE-2023-23021MEDIUM6.1Cross Site Scripting (XSS) vulnerability in sourcecodester oretnom23 pos point sale system 1.0, allows attackers to exec...
CVE-2023-23019MEDIUM5.4Cross site scripting (XSS) vulnerability in file main.php in sourcecodester oretnom23 Blog Site 1.0 via the name and ema...
CVE-2023-7241HIGH7.9Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious s...
CVE-2023-49606CRITICAL9.8A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A...
CVE-2023-47212CRITICAL9.8A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially craft...
CVE-2023-47166HIGH8.8A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A spec...
CVE-2023-40533Rejected reason: This CVE ID is a duplicate of CVE-2022-40468
CVE-2023-52653MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix a memleak in gss_import_v2_context The...
CVE-2023-52652MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: NTB: fix possible name leak in ntb_register_device(...
CVE-2023-52651Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-52650MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tegra: dsi: Add missing check for of_find_devic...
CVE-2023-52649HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Avoid reading beyond LUT array When the ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now