2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-25837HIGH8.4There is a Cross‑Site Scripting (XSS) vulnerability in Esri ArcGIS Enterprise Sites versions 10.9 and below that may all...
CVE-2023-3813HIGH7.5The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6....
CVE-2023-3808HIGH8.8A vulnerability was found in Hospital Management System 1.0 and classified as critical. Affected by this issue is some u...
CVE-2023-3807HIGH8.8A vulnerability has been found in Campcodes Beauty Salon Management System 1.0 and classified as critical. Affected by t...
CVE-2023-25835HIGH8.4There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS Sites versions 11.1 and below that ...
CVE-2023-3797HIGH8.8A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention...
CVE-2023-3796HIGH8.8A vulnerability, which was classified as problematic, has been found in Bug Finder Foody Friend 1.0. Affected by this is...
CVE-2023-37650HIGH8.8A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Admi...
CVE-2023-37649HIGH7.5Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access ...
CVE-2023-34625HIGH8.1ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mech...
CVE-2023-30200HIGH7.5In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Adv...
CVE-2023-37601HIGH7.5Office Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the componen...
CVE-2023-31462HIGH8.8An issue was discovered in SteelSeries GG 36.0.0. An attacker can change values in an unencrypted database that is writa...
CVE-2023-31461HIGH7.5Attackers can exploit an open API listener on SteelSeries GG 36.0.0 to create a sub-application that will be executed au...
CVE-2023-34966HIGH7.5An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC ...
CVE-2023-37290HIGH7.5 InfoDoc Document On-line Submission and Approval System lacks sufficient restrictions on the available tags within its ...
CVE-2023-37362HIGH8.8Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing cred...
CVE-2023-36853HIGH7.8 ​In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containin...
CVE-2023-34429HIGH7.5 Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending...
CVE-2023-34394HIGH7.8 In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or d...
CVE-2023-32657HIGH7.5 Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with...
CVE-2023-26217HIGH8.8The Data Exchange Add-on component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerabili...
CVE-2023-37899HIGH7.5Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socke...
CVE-2023-37276HIGH7.5aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled w...
CVE-2023-3467HIGH8Privilege Escalation to root administrator (nsroot)

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now