2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-44915HIGH7.1A cross-site scripting (XSS) vulnerability in the component /Login.php of c3crm up to v3.0.4 allows attackers to execute...
CVE-2023-50450HIGH8.4An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified acti...
CVE-2023-47294HIGH8.1An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, l...
CVE-2023-20599HIGH7.9Improper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto C...
CVE-2023-26005HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2023-25999HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2023-26003HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vipul Jariwala WP ...
CVE-2023-25995HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2023-2921HIGH8.8The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL st...
CVE-2023-34873HIGH8.7On MOBOTIX P3 cameras before MX-V4.7.2.18 and Mx6 cameras before MX-V5.2.0.61, the tcpdump feature does not properly val...
CVE-2023-47466HIGH7.1TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in whi...
CVE-2023-7239HIGH7.5The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id paramete...
CVE-2023-7231HIGH7.3The illi Link Party! WordPress plugin through 1.0 lacks proper access controls, allowing unauthenticated visitors to del...
CVE-2023-7197HIGH7.1The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisa...
CVE-2023-7174HIGH7.1The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisa...
CVE-2023-5934HIGH7.3The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when ...
CVE-2023-31359HIGH7.8Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, pote...
CVE-2023-31358HIGH7.8A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, pote...
CVE-2023-53145HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btsdio: fix use after free bug in btsdio...
CVE-2023-53142HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ice: copy last block omitted in ice_get_module_eepr...
CVE-2023-53138HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: caif: Fix use-after-free in cfusbl_device_noti...
CVE-2023-53136HIGH7.1In the Linux kernel, the following vulnerability has been resolved: af_unix: fix struct pid leaks in OOB support syzbo...
CVE-2023-53135HIGH7.1In the Linux kernel, the following vulnerability has been resolved: riscv: Use READ_ONCE_NOCHECK in imprecise unwinding...
CVE-2023-53123HIGH7.8In the Linux kernel, the following vulnerability has been resolved: PCI: s390: Fix use-after-free of PCI resources with...
CVE-2023-53117HIGH7.1In the Linux kernel, the following vulnerability has been resolved: fs: prevent out-of-bounds array speculation when cl...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now