2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-33198HIGH7.5tgstation-server is a production scale tool for BYOND server management. The DreamMaker API (DMAPI) chat channel cache c...
CVE-2023-33175HIGH7.5ToUI is a Python package for creating user interfaces (websites and desktop apps) from HTML. ToUI is using Flask-Caching...
CVE-2023-26130HIGH8.8Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is ...
CVE-2023-32698HIGH7.1nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packag...
CVE-2023-27988HIGH7.2The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 ...
CVE-2023-30253HIGH8.8Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instea...
CVE-2023-31874HIGH8.8Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_pro...
CVE-2023-30570HIGH7.5pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticat...
CVE-2023-30350HIGH8.8FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin ...
CVE-2023-29380HIGH7.5Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames.
CVE-2023-32763HIGH7.5An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file wi...
CVE-2023-31873HIGH7.8Gin 0.7.4 allows execution of arbitrary code when a crafted file is opened, e.g., via require('child_process').
CVE-2023-33291HIGH7.4In ebankIT 6, the public endpoints /public/token/Email/generate and /public/token/SMS/generate allow generation of OTP m...
CVE-2023-33926HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps plugin <= 1.11.7 versions.
CVE-2023-33316HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9....
CVE-2023-33313HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ThemeinProgress WIP Custom Login plugin <= 1.2.9 versions.
CVE-2023-33931HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <= 4.6.4 versions.
CVE-2023-33315HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Stephen Darlington, Wandle Software Limited Smart App Banner plugin <...
CVE-2023-33314HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions.
CVE-2023-33212HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0...
CVE-2023-2950HIGH8.1Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2946HIGH8.1Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2943HIGH8.8Code Injection in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2942HIGH8.1Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-32695HIGH7.5socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now