2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5679HIGH7.5A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive re...
CVE-2023-5517HIGH7.5A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redir...
CVE-2023-4408HIGH7.5The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not ca...
CVE-2023-6072MEDIUM5.4 A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authentica...
CVE-2023-51440HIGH7.5A vulnerability has been identified in SIMATIC CP 343-1 (6GK7343-1EX30-0XE0) (All versions), SIMATIC CP 343-1 Lean (6GK7...
CVE-2023-50236HIGH7.8A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to ...
CVE-2023-49125HIGH7.8A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.263), Parasolid V35.1 (All versions < V35.1...
CVE-2023-48364MEDIUM6.5A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions <...
CVE-2023-48363MEDIUM6.5A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions <...
CVE-2023-6815MEDIUM6.5Incorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series Safety CPU R08/16/32/...
CVE-2023-52431HIGH8.8The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism v...
CVE-2023-50358MEDIUM5.8An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2023-47218HIGH8.3An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2023-52060MEDIUM4.3A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via...
CVE-2023-52059MEDIUM5.4A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML ...
CVE-2023-49339MEDIUM6.5Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/s...
CVE-2023-42374CRITICAL9.8An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denia...
CVE-2023-52430MEDIUM6.1The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload ...
CVE-2023-28018MEDIUM6.5HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a special...
CVE-2023-7233MEDIUM4.8The GigPress WordPress plugin through 2.3.29 does not sanitise and escape some of its settings, which could allow high p...
CVE-2023-6591MEDIUM4.8The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high p...
CVE-2023-6501MEDIUM4.3The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could...
CVE-2023-6499MEDIUM5.4The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well...
CVE-2023-6294HIGH7.2The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could...
CVE-2023-6082MEDIUM5.4The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high pr...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now