2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6335HIGH7.8Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows ...
CVE-2023-6334HIGH7.8Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Window...
CVE-2023-5097MEDIUM5.5Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Wor...
CVE-2023-7234MEDIUM5.3 OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's se...
CVE-2023-52041CRITICAL9.8An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 ...
CVE-2023-51381Rejected reason: This CVE ID has been rejected or withdrawn by GitHub.
CVE-2023-49351CRITICAL9.8A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows atta...
CVE-2023-37523CRITICAL9.8Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker t...
CVE-2023-22525Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2023-22520Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2023-22514HIGH7.8This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and ...
CVE-2023-22512HIGH7.5This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and S...
CVE-2023-22510Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2023-22507Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2023-22502Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
CVE-2023-4969MEDIUM6.5A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU me...
CVE-2023-7154MEDIUM4.8The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings,...
CVE-2023-7151MEDIUM6.1The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before o...
CVE-2023-7125MEDIUM4.3The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on t...
CVE-2023-7084MEDIUM5.4The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authen...
CVE-2023-7083MEDIUM5.4The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as w...
CVE-2023-6824MEDIUM6.5The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX act...
CVE-2023-6741MEDIUM4.3The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX act...
CVE-2023-6732MEDIUM4.8The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which c...
CVE-2023-6592MEDIUM5.3The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export fi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now