2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-47123MEDIUM5.4iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an...
CVE-2023-45808MEDIUM5.4iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in t...
CVE-2023-44396MEDIUM5.4iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.1...
CVE-2023-43790MEDIUM5.4iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fie...
CVE-2023-38511MEDIUM4.3iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure...
CVE-2023-52144MEDIUM5.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Ma...
CVE-2023-7201MEDIUM6.5The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high ...
CVE-2023-6067MEDIUM5.4The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes ...
CVE-2023-6494MEDIUM4.4The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set...
CVE-2023-52211MEDIUM5.3Missing Authorization vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.0...
CVE-2023-51515HIGH8.8Missing Authorization vulnerability in Undsgn Uncode Core allows Privilege Escalation.This issue affects Uncode Core: fr...
CVE-2023-51499MEDIUM4.3Missing Authorization vulnerability in WooCommerce WooCommerce Shipping Per Product.This issue affects WooCommerce Shipp...
CVE-2023-51409CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect...
CVE-2023-47714MEDIUM5.4IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scri...
CVE-2023-49528HIGH8Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code an...
CVE-2023-44856MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitra...
CVE-2023-44855MEDIUM6.5Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrar...
CVE-2023-44857HIGH8.1An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to ...
CVE-2023-44854MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitra...
CVE-2023-44853MEDIUM4.8\An issue was discovered in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a cr...
CVE-2023-44852HIGH8.2Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitra...
CVE-2023-50307MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site sc...
CVE-2023-45186MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site sc...
CVE-2023-6678MEDIUM6.5An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 1...
CVE-2023-6489MEDIUM6.5A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now