2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6004MEDIUM4.8A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syn...
CVE-2023-50253MEDIUM6.5Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve ...
CVE-2023-46742MEDIUM6.5CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret ...
CVE-2023-46741CRITICAL9.8CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 th...
CVE-2023-46740CRITICAL9.8CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string...
CVE-2023-46739MEDIUM5.9CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master compone...
CVE-2023-46738MEDIUM6.5CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in v...
CVE-2023-30617MEDIUM6.5Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to v...
CVE-2023-45559HIGH8.2An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel acce...
CVE-2023-50093MEDIUM6.1APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.
CVE-2023-37607HIGH7.5Directory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensiti...
CVE-2023-50092MEDIUM6.1APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-39655CRITICAL9.6A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a spe...
CVE-2023-37608HIGH7.5An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive informat...
CVE-2023-51785HIGH7.5Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1....
CVE-2023-51784CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLon...
CVE-2023-7068MEDIUM6.5The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to un...
CVE-2023-6984MEDIUM4.3The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-...
CVE-2023-6747MEDIUM5.4The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2023-6621MEDIUM6.1The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in ...
CVE-2023-52314CRITICAL9.8PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbi...
CVE-2023-52313HIGH7.5FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of...
CVE-2023-52312HIGH7.5Nullptr dereference in paddle.crop in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of ser...
CVE-2023-52311CRITICAL9.8PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary c...
CVE-2023-52310CRITICAL9.8PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now