2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-54375Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
CVE-2023-37507HIGH7.5HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon...
CVE-2023-37508MEDIUM6.1HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this v...
CVE-2023-54366HIGH8.8SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELE...
CVE-2023-49900CRITICAL9.8An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in t...
CVE-2023-49899CRITICAL9.8An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the ori...
CVE-2023-37524HIGH7.8HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of servi...
CVE-2023-20572MEDIUM5.6An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against th...
CVE-2023-20540LOW1.8An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against th...
CVE-2023-54365HIGH8.7Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri...
CVE-2023-33854MEDIUM5.3IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow a...
CVE-2023-45796HIGH8.1A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to an...
CVE-2023-45795HIGH7.8A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticat...
CVE-2023-54357HIGH8.7Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attacker...
CVE-2023-54353HIGH8.5Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attack...
CVE-2023-32959MEDIUM4.3Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access ...
CVE-2023-25969MEDIUM5.4Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectl...
CVE-2023-40200MEDIUM5.3Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider an...
CVE-2023-33999HIGH7.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Lo...
CVE-2023-43688HIGH7.5An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow i...
CVE-2023-43686MEDIUM6.2An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox prefere...
CVE-2023-29146HIGH8.2The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes trunca...
CVE-2023-54352CRITICAL9.8WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2023-54351HIGH7.2WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attac...
CVE-2023-54350HIGH8.7WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now