2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-5199HIGH8.8The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and ...
CVE-2023-5833HIGH8.8Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.
CVE-2023-5844HIGH7.2Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.
CVE-2023-44141HIGH7.8Inkdrop prior to v5.6.0 allows a local attacker to conduct a code injection attack by having a legitimate user open a sp...
CVE-2023-46865HIGH7.2/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PH...
CVE-2023-46863HIGH7.5Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/downl...
CVE-2023-40685HIGH7.8Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability...
CVE-2023-5840HIGH8.8Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.
CVE-2023-5839HIGH7.8Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.
CVE-2023-40686HIGH7.8Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability...
CVE-2023-5426HIGH7.5The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa...
CVE-2023-5425HIGH8.8The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa...
CVE-2023-46215HIGH7.5Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensi...
CVE-2023-46468HIGH7.8An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the cus...
CVE-2023-43322HIGH8.8ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8....
CVE-2023-46587HIGH7.8Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted...
CVE-2023-5834HIGH7.8HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, int...
CVE-2023-44480HIGH8.8Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setcasu...
CVE-2023-40140HIGH7.8In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code du...
CVE-2023-40131HIGH7In GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local es...
CVE-2023-40130HIGH7.8In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. Th...
CVE-2023-40129HIGH8.8In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could...
CVE-2023-40128HIGH7.8In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could l...
CVE-2023-40125HIGH7.8In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. Th...
CVE-2023-40120HIGH7.8In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now