2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-45677HIGH7.8stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of boun...
CVE-2023-45676HIGH7.8stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of boun...
CVE-2023-45675HIGH7.8stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of boun...
CVE-2023-45667HIGH7.5stb_image is a single file MIT licensed library for processing images. If `stbi__load_gif_main` in `stbi_load_gif_from_...
CVE-2023-45664HIGH8.8stb_image is a single file MIT licensed library for processing images. A crafted image file can trigger `stbi__load_gif_...
CVE-2023-45662HIGH8.1stb_image is a single file MIT licensed library for processing images. When `stbi_set_flip_vertically_on_load` is set to...
CVE-2023-45661HIGH7.1stb_image is a single file MIT licensed library for processing images. A crafted image file may trigger out of bounds me...
CVE-2023-32786HIGH7.5In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrar...
CVE-2023-5681HIGH7.2A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. This ...
CVE-2023-46117HIGH8.8reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform sc...
CVE-2023-45805HIGH7.8pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `...
CVE-2023-5690HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.2.2.
CVE-2023-5687HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository mosparo/mosparo prior to 1.0.3.
CVE-2023-5686HIGH8.8Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
CVE-2023-23373HIGH8.8An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow ...
CVE-2023-3487HIGH7.8An integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when readi...
CVE-2023-34045HIGH7.8VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation f...
CVE-2023-34046HIGH7VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during instal...
CVE-2023-5602HIGH8.8The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2023-4999HIGH8.8The Horizontal scrolling announcement plugin for WordPress is vulnerable to SQL Injection via the plugin's [horizontal-s...
CVE-2023-4668HIGH7.5The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 v...
CVE-2023-4386HIGH8.1The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 ...
CVE-2023-5524HIGH7.3Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before ...
CVE-2023-5523HIGH7.8Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versi...
CVE-2023-5414HIGH7.2The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 v...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now