2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-2460HIGH7.1Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who...
CVE-2023-31435HIGH8.1Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire p...
CVE-2023-31433HIGH8.8A SQL injection issue in Logbuch in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allows authenticated atta...
CVE-2023-30944HIGH7.3The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki ...
CVE-2023-30403HIGH7.5An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows ...
CVE-2023-26546HIGH8.8European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Si...
CVE-2023-30861HIGH7.5Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containi...
CVE-2023-32007HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option s...
CVE-2023-1196HIGH8.8The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user ...
CVE-2023-1809HIGH7.5The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowin...
CVE-2023-1669HIGH7.2The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-p...
CVE-2023-0924HIGH7.2The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowin...
CVE-2023-21666HIGH7.8Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
CVE-2023-21665HIGH7.8Memory corruption in Graphics while importing a file.
CVE-2023-21642HIGH7.8Memory corruption in HAB Memory management due to broad system privileges via physical address.
CVE-2023-27035HIGH7.5An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio an...
CVE-2023-22922HIGH7.5A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remot...
CVE-2023-22921HIGH7.5A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could al...
CVE-2023-22919HIGH8.8The post-authentication command injection vulnerability in the Zyxel NBG6604 firmware version V1.01(ABIR.0)C0 could allo...
CVE-2023-25492HIGH8.8A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined ...
CVE-2023-0683HIGH8.8A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API ca...
CVE-2023-30063HIGH7.5D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.
CVE-2023-30061HIGH7.5D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.
CVE-2023-0896HIGH8.8A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device...
CVE-2023-2236HIGH7.8A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escala...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now