2023 CVE Vulnerabilities
31,267 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-0996 | HIGH | 7.8 | 0.3% | Feb 24, 2023 | There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker coul... |
| CVE-2023-0994 | HIGH | 7.5 | 1.0% | Feb 24, 2023 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8... |
| CVE-2023-23295 | HIGH | 8.8 | 3.8% | Feb 23, 2023 | Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysC... |
| CVE-2023-23294 | HIGH | 8.8 | 2.7% | Feb 23, 2023 | Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can mod... |
| CVE-2023-25824 | HIGH | 7.5 | 1.1% | Feb 23, 2023 | Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly ... |
| CVE-2023-26325 | HIGH | 8.8 | 0.9% | Feb 23, 2023 | The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerabili... |
| CVE-2023-24317 | HIGH | 8.1 | 1.7% | Feb 23, 2023 | Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_or... |
| CVE-2023-23919 | HIGH | 7.5 | 2.2% | Feb 23, 2023 | A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not cl... |
| CVE-2023-23918 | HIGH | 7.5 | 2.0% | Feb 23, 2023 | A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to... |
| CVE-2023-23917 | HIGH | 8.8 | 1.0% | Feb 23, 2023 | A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the ... |
| CVE-2023-20050 | HIGH | 7.8 | 0.3% | Feb 23, 2023 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com... |
| CVE-2023-20011 | HIGH | 8.8 | 0.4% | Feb 23, 2023 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and C... |
| CVE-2023-24415 | HIGH | 8.8 | 0.3% | Feb 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions. |
| CVE-2023-0988 | HIGH | 8.8 | 0.5% | Feb 23, 2023 | A vulnerability, which was classified as problematic, has been found in SourceCodester Online Pizza Ordering System 1.0.... |
| CVE-2023-24384 | HIGH | 8.8 | 0.3% | Feb 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions. |
| CVE-2023-23659 | HIGH | 8.8 | 0.3% | Feb 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in MainWP Matomo Extension <= 4.0.4 versions. |
| CVE-2023-26462 | HIGH | 8.1 | 1.1% | Feb 23, 2023 | ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usab... |
| CVE-2023-22974 | HIGH | 7.5 | 1.9% | Feb 22, 2023 | A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controll... |
| CVE-2023-22973 | HIGH | 8.8 | 1.8% | Feb 22, 2023 | A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated... |
| CVE-2023-0104 | HIGH | 7.8 | 21.8% | Feb 22, 2023 | The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious pr... |
| CVE-2023-0966 | HIGH | 8.8 | 0.8% | Feb 22, 2023 | A vulnerability classified as problematic was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerab... |
| CVE-2023-0941 | HIGH | 8.8 | 0.6% | Feb 22, 2023 | Use after free in Prompts in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap... |
| CVE-2023-0933 | HIGH | 8.8 | 0.6% | Feb 22, 2023 | Integer overflow in PDF in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap c... |
| CVE-2023-0932 | HIGH | 8.8 | 0.6% | Feb 22, 2023 | Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the... |
| CVE-2023-0931 | HIGH | 8.8 | 0.6% | Feb 22, 2023 | Use after free in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap c... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now