2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-54359HIGH8.8WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated ...
CVE-2023-7343HIGH8.5Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01 prior to 08.3.02 contain an arbitrary code execution vul...
CVE-2023-7342HIGH8.8HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege escalation vulnerability that allows authentic...
CVE-2023-7338HIGH7.7Ruckus Unleashed contains a remote code execution vulnerability in the web-based management interface that allows authen...
CVE-2023-43010HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14....
CVE-2023-7337HIGH7.5The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js...
CVE-2023-31044HIGH8.8An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, u...
CVE-2023-31364HIGH8.3Improper handling of direct memory writes in the input-output memory management unit could allow a malicious guest virtu...
CVE-2023-31323HIGH8.4Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Gl...
CVE-2023-31313HIGH7.2An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to sen...
CVE-2023-31324HIGH7.8A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify ...
CVE-2023-20548HIGH7.8A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt...
CVE-2023-20514HIGH8.7Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary...
CVE-2023-38010HIGH7.5IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the syste...
CVE-2023-7335HIGH8.7EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export ...
CVE-2023-54340HIGH8.8WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by mani...
CVE-2023-54338HIGH8.5Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbit...
CVE-2023-54336HIGH8.5Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to...
CVE-2023-54333HIGH8.8Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attac...
CVE-2023-54331HIGH8.5Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra...
CVE-2023-53984HIGH8.5Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows loca...
CVE-2023-36331HIGH8.2Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' ...
CVE-2023-49186HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KlbTheme Ma...
CVE-2023-7332HIGH7.1PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handl...
CVE-2023-54163HIGH8.8NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attac...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now