2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49624CRITICAL9.8Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter ...
CVE-2023-49622CRITICAL9.8Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' paramete...
CVE-2023-6992MEDIUM5.5Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algori...
CVE-2023-7044MEDIUM5.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2023-6944MEDIUM5.7A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the fron...
CVE-2023-50630MEDIUM6.1Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to execute arbitrary code v...
CVE-2023-50082HIGH7.5Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive in...
CVE-2023-41784MEDIUM5.5 Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro
CVE-2023-52322MEDIUM6.1ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not...
CVE-2023-29962MEDIUM6.5S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.
CVE-2023-6738MEDIUM5.4The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2023-6733MEDIUM6.5The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2023-6498MEDIUM4.8The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set...
CVE-2023-5138MEDIUM6.8Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, ex...
CVE-2023-50256HIGH7.5Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registratio...
CVE-2023-52141Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA po...
CVE-2023-52140Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA po...
CVE-2023-6540HIGH7.5A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an att...
CVE-2023-6338HIGH7.8Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an a...
CVE-2023-49442CRITICAL9.8Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary ...
CVE-2023-5881HIGH8.2Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Gar...
CVE-2023-5880HIGH8.8When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode t...
CVE-2023-5879MEDIUM6.8Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Applicat...
CVE-2023-50090CRITICAL9.8Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write a...
CVE-2023-46929HIGH7.5An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tool...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now