2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-1304HIGH8.8An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perfo...
CVE-2023-25923HIGH7.5IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that...
CVE-2023-27874HIGH8.8IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot...
CVE-2023-27871HIGH7.5IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, u...
CVE-2023-27842HIGH8.8Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execut...
CVE-2023-1314HIGH7.8A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a l...
CVE-2023-27984HIGH8.8A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, pote...
CVE-2023-1545HIGH7.5SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.
CVE-2023-27981HIGH8.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could ...
CVE-2023-27978HIGH7.8A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpreta...
CVE-2023-1462HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Aut...
CVE-2023-27982HIGH8.8A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manip...
CVE-2023-27980HIGH8.8A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could...
CVE-2023-1543HIGH8.8Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-27578HIGH7.5Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05...
CVE-2023-27586HIGH7.1CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to e...
CVE-2023-0940HIGH8.8The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not imple...
CVE-2023-0875HIGH8.8The WP Meta SEO WordPress plugin before 4.5.3 does not properly sanitize and escape inputs into SQL queries, leading to ...
CVE-2023-0865HIGH8.8The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to ...
CVE-2023-0631HIGH8.8The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that conc...
CVE-2023-0630HIGH8.8The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that conca...
CVE-2023-0340HIGH8.8The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which coul...
CVE-2023-28118HIGH7.5kaml provides YAML support for kotlinx.serialization. Prior to version 0.53.0, applications that use kaml to parse untru...
CVE-2023-26513HIGH7.5Excessive Iteration vulnerability in Apache Software Foundation Apache Sling Resource Merger.This issue affects Apache S...
CVE-2023-23721HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in David Gwyer Admin Log plugin <= 1.50 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now