2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-51837CRITICAL9.8Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.
CVE-2023-51813MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote at...
CVE-2023-37571MEDIUM6.1Softing TH SCOPE through 3.70 allows XSS.
CVE-2023-4554MEDIUM6.5Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Serv...
CVE-2023-4553MEDIUM5.3Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder...
CVE-2023-4552HIGH7.1Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenti...
CVE-2023-4551HIGH8.8Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBu...
CVE-2023-4550HIGH7.5Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on W...
CVE-2023-49038HIGH7.2Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbit...
CVE-2023-51842HIGH7.5An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16.
CVE-2023-51840CRITICAL9.8DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.
CVE-2023-51839CRITICAL9.1DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm.
CVE-2023-30970MEDIUM6.5Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated use...
CVE-2023-22836MEDIUM5.4In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from t...
CVE-2023-40551MEDIUM5.1A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposu...
CVE-2023-40550MEDIUM5.5An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensi...
CVE-2023-40549MEDIUM5.5An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE bin...
CVE-2023-40546MEDIUM5.5A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new varia...
CVE-2023-1705HIGH7.8Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) all...
CVE-2023-7204HIGH7.5The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provid...
CVE-2023-7200MEDIUM6.1The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page...
CVE-2023-7199MEDIUM5.3The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthentica...
CVE-2023-7089MEDIUM5.4The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a rol...
CVE-2023-7074HIGH8.8The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, w...
CVE-2023-6946HIGH8.8The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which cou...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now