2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6145CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in İstanbul Soft Info...
CVE-2023-6122MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in İstanbul Soft Info...
CVE-2023-49162HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BigCommerce BigCommerce For WordPress.This i...
CVE-2023-48288HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HM Plugin WordPress Job Board and Recruitmen...
CVE-2023-2487HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orde...
CVE-2023-28421HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Winwar Media WordPress Email Marketing Plugi...
CVE-2023-49826CRITICAL9.8Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce Wor...
CVE-2023-49778CRITICAL9.8Deserialization of Untrusted Data vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a th...
CVE-2023-49762HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AppMySite AppMySite – Create an app with the...
CVE-2023-32242CRITICAL9.8Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects W...
CVE-2023-5594HIGH8.6Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certifi...
CVE-2023-51656CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.1...
CVE-2023-50481HIGH7.5An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak en...
CVE-2023-50477CRITICAL9.8An issue was discovered in nos client version 0.6.6, allows remote attackers to escalate privileges via getRPCEndpoint.j...
CVE-2023-50475CRITICAL9.1An issue was discovered in bcoin-org bcoin version 2.2.0, allows remote attackers to obtain sensitive information via we...
CVE-2023-50473MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in bill-ahmed qbit-matUI version 1.16.4, allows remote attackers to obtain sens...
CVE-2023-5989MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uyumsoft Inform...
CVE-2023-5988MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uyumsoft Informati...
CVE-2023-51655CRITICAL9.8In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin ...
CVE-2023-50783MEDIUM6.5Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the vari...
CVE-2023-49920MEDIUM6.5Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET reque...
CVE-2023-48291MEDIUM4.3Apache Airflow, in versions prior to 2.8.0, contains a security vulnerability that allows an authenticated user with lim...
CVE-2023-47265MEDIUM5.4Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded...
CVE-2023-2585HIGH8.1Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client coul...
CVE-2023-7026MEDIUM6.5A vulnerability was found in Lightxun IPTV Gateway up to 20231208. It has been rated as problematic. This issue affects ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now