2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-7090HIGH8.8A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated...
CVE-2023-49594MEDIUM6.5An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthentica...
CVE-2023-7008MEDIUM5.9A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed ...
CVE-2023-6744MEDIUM5.4The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all...
CVE-2023-5962MEDIUM6.5A weak cryptographic algorithm vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prio...
CVE-2023-5961HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and...
CVE-2023-7002HIGH7.2The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1....
CVE-2023-6972CRITICAL9.8The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 vi...
CVE-2023-6971CRITICAL9.8The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'con...
CVE-2023-51386LOW3.3Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously ...
CVE-2023-51651LOW3.3AWS SDK for PHP is the Amazon Web Services software development kit for PHP. Within the scope of requests to S3 object k...
CVE-2023-51650HIGH7.5Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration i...
CVE-2023-51451MEDIUM4.3Symbolicator is a service used in Sentry. Starting in Symbolicator version 0.3.3 and prior to version 21.12.1, an attack...
CVE-2023-51449HIGH7.5Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine lear...
CVE-2023-51387HIGH8.8Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. Th...
CVE-2023-50928CRITICAL9"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneousl...
CVE-2023-50924MEDIUM5.4Englesystem is a shift planning system for chaos events. Engelsystem prior to v3.4.1 performed insufficient validation o...
CVE-2023-50731CRITICAL9.1MindsDB is a SQL Server for artificial intelligence. Prior to version 23.11.4.1, the `put` method in `mindsdb/mindsdb/ap...
CVE-2023-50730HIGH7.5Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification require...
CVE-2023-50727MEDIUM6.1Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them...
CVE-2023-50725MEDIUM6.1Resque is a Redis-backed Ruby library for creating background jobs, placing them on multiple queues, and processing them...
CVE-2023-50712MEDIUM5.4Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations....
CVE-2023-51035CRITICAL9.8TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost ...
CVE-2023-51034CRITICAL9.8TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareF...
CVE-2023-51033CRITICAL9.8TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi setOpModeCfg in...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now