2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32064MEDIUM4.3OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can acce...
CVE-2023-32063MEDIUM5OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access...
CVE-2023-6219HIGH7.2The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the...
CVE-2023-5960MEDIUM5.5An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.5...
CVE-2023-5797MEDIUM5.5An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 t...
CVE-2023-5650MEDIUM5.5An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, ...
CVE-2023-4398HIGH7.5An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ...
CVE-2023-4397MEDIUM4.4A buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmware version 5.37, US...
CVE-2023-47503CRITICAL9.8An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the log...
CVE-2023-37926MEDIUM5.5A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware ve...
CVE-2023-37925MEDIUM5.5An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 t...
CVE-2023-35139MEDIUM6.1A cross-site scripting (XSS) vulnerability in the CGI program of the Zyxel ATP series firmware versions 5.10 through 5.3...
CVE-2023-35136MEDIUM5.5An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 throug...
CVE-2023-30585HIGH7.5A vulnerability has been identified in the Node.js (.msi version) installation process, specifically affecting Windows u...
CVE-2023-47437MEDIUM5.4A vulnerability has been identified in Pachno 1.0.6 allowing an authenticated attacker to execute a cross-site scripting...
CVE-2023-29770HIGH8.8In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file w...
CVE-2023-49145MEDIUM5.4Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user ...
CVE-2023-48188CRITICAL9.8SQL injection vulnerability in PrestaShop opartdevis v.4.5.18 thru v.4.6.12 allows a remote attacker to execute arbitrar...
CVE-2023-46480CRITICAL9.8An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ...
CVE-2023-46355MEDIUM5.3In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal informati...
CVE-2023-46349CRITICAL9.8In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop,...
CVE-2023-42366MEDIUM5.5A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.
CVE-2023-42365MEDIUM5.5A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar functio...
CVE-2023-42364MEDIUM5.5A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk patte...
CVE-2023-5885MEDIUM6.5The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now