2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-54359 | HIGH | 8.8 | 0.3% | Apr 9, 2026 | WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated ... |
| CVE-2023-7343 | HIGH | 8.5 | 0.1% | Apr 2, 2026 | Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01 prior to 08.3.02 contain an arbitrary code execution vul... |
| CVE-2023-7342 | HIGH | 8.8 | 0.3% | Apr 2, 2026 | HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege escalation vulnerability that allows authentic... |
| CVE-2023-7338 | HIGH | 7.7 | 0.5% | Mar 26, 2026 | Ruckus Unleashed contains a remote code execution vulnerability in the web-based management interface that allows authen... |
| CVE-2023-43010 | HIGH | 8.8 | 0.9% | Mar 12, 2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.... |
| CVE-2023-7337 | HIGH | 7.5 | 1.3% | Mar 4, 2026 | The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js... |
| CVE-2023-31044 | HIGH | 8.8 | 0.2% | Mar 3, 2026 | An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, u... |
| CVE-2023-31364 | HIGH | 8.3 | 0.2% | Feb 26, 2026 | Improper handling of direct memory writes in the input-output memory management unit could allow a malicious guest virtu... |
| CVE-2023-31323 | HIGH | 8.4 | 0.1% | Feb 12, 2026 | Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Gl... |
| CVE-2023-31313 | HIGH | 7.2 | 0.1% | Feb 12, 2026 | An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to sen... |
| CVE-2023-31324 | HIGH | 7.8 | 0.1% | Feb 11, 2026 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify ... |
| CVE-2023-20548 | HIGH | 7.8 | 0.1% | Feb 11, 2026 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt... |
| CVE-2023-20514 | HIGH | 8.7 | 0.1% | Feb 11, 2026 | Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary... |
| CVE-2023-38010 | HIGH | 7.5 | 0.3% | Feb 4, 2026 | IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the syste... |
| CVE-2023-7335 | HIGH | 8.7 | 0.7% | Jan 22, 2026 | EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export ... |
| CVE-2023-54340 | HIGH | 8.8 | 0.3% | Jan 13, 2026 | WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by mani... |
| CVE-2023-54338 | HIGH | 8.5 | 0.1% | Jan 13, 2026 | Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbit... |
| CVE-2023-54336 | HIGH | 8.5 | 0.2% | Jan 13, 2026 | Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to... |
| CVE-2023-54333 | HIGH | 8.8 | 0.3% | Jan 13, 2026 | Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attac... |
| CVE-2023-54331 | HIGH | 8.5 | 0.2% | Jan 13, 2026 | Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra... |
| CVE-2023-53984 | HIGH | 8.5 | 0.2% | Jan 13, 2026 | Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows loca... |
| CVE-2023-36331 | HIGH | 8.2 | 0.2% | Jan 12, 2026 | Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' ... |
| CVE-2023-49186 | HIGH | 7.1 | 0.1% | Jan 5, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KlbTheme Ma... |
| CVE-2023-7332 | HIGH | 7.1 | 0.4% | Dec 31, 2025 | PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handl... |
| CVE-2023-54163 | HIGH | 8.8 | 0.3% | Dec 30, 2025 | NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attac... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now