2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-5872 | MEDIUM | 4.3 | 0.3% | Apr 16, 2026 | In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames th... |
| CVE-2023-3634 | HIGH | 8.8 | 0.5% | Apr 16, 2026 | In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of u... |
| CVE-2023-54364 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to i... |
| CVE-2023-54363 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to ... |
| CVE-2023-54362 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to ... |
| CVE-2023-54361 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inje... |
| CVE-2023-54360 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicio... |
| CVE-2023-54359 | HIGH | 8.8 | 0.3% | Apr 9, 2026 | WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated ... |
| CVE-2023-54358 | MEDIUM | 6.1 | 0.3% | Apr 9, 2026 | WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated ... |
| CVE-2023-46945 | CRITICAL | 9.1 | 0.2% | Apr 8, 2026 | QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request |
| CVE-2023-7343 | HIGH | 8.5 | 0.1% | Apr 2, 2026 | Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01 prior to 08.3.02 contain an arbitrary code execution vul... |
| CVE-2023-7342 | HIGH | 8.8 | 0.3% | Apr 2, 2026 | HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege escalation vulnerability that allows authentic... |
| CVE-2023-7340 | MEDIUM | 4.3 | 0.3% | Mar 27, 2026 | Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed... |
| CVE-2023-7339 | MEDIUM | 6.5 | 0.4% | Mar 27, 2026 | Stack-based buffer overflow vulnerability in Softing Industrial Automation GmbH gateways allows overflow buffers. This i... |
| CVE-2023-7338 | HIGH | 7.7 | 0.5% | Mar 26, 2026 | Ruckus Unleashed contains a remote code execution vulnerability in the web-based management interface that allows authen... |
| CVE-2023-40693 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.... |
| CVE-2023-43010 | HIGH | 8.8 | 0.9% | Mar 12, 2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.... |
| CVE-2023-27573 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0... |
| CVE-2023-7337 | HIGH | 7.5 | 1.3% | Mar 4, 2026 | The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js... |
| CVE-2023-31044 | HIGH | 8.8 | 0.2% | Mar 3, 2026 | An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, u... |
| CVE-2023-31364 | HIGH | 8.3 | 0.2% | Feb 26, 2026 | Improper handling of direct memory writes in the input-output memory management unit could allow a malicious guest virtu... |
| CVE-2023-38005 | MEDIUM | 4.3 | 0.2% | Feb 17, 2026 | IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could allow an authenticated user to perform unauth... |
| CVE-2023-38265 | MEDIUM | 5.3 | 0.2% | Feb 17, 2026 | IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an un... |
| CVE-2023-45291 | — | — | — | Feb 13, 2026 | Rejected reason: reserved but not needed |
| CVE-2023-31323 | HIGH | 8.4 | 0.1% | Feb 12, 2026 | Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Gl... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now