2023 CVE Vulnerabilities

31,267 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-0996HIGH7.8 There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker coul...
CVE-2023-0994HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8...
CVE-2023-23295HIGH8.8Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysC...
CVE-2023-23294HIGH8.8Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can mod...
CVE-2023-25824HIGH7.5Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly ...
CVE-2023-26325HIGH8.8The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerabili...
CVE-2023-24317HIGH8.1Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_or...
CVE-2023-23919HIGH7.5A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not cl...
CVE-2023-23918HIGH7.5A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to...
CVE-2023-23917HIGH8.8A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the ...
CVE-2023-20050HIGH7.8A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com...
CVE-2023-20011HIGH8.8A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and C...
CVE-2023-24415HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions.
CVE-2023-0988HIGH8.8A vulnerability, which was classified as problematic, has been found in SourceCodester Online Pizza Ordering System 1.0....
CVE-2023-24384HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart <= 1.4.4 versions.
CVE-2023-23659HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in MainWP Matomo Extension <= 4.0.4 versions.
CVE-2023-26462HIGH8.1ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usab...
CVE-2023-22974HIGH7.5A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controll...
CVE-2023-22973HIGH8.8A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated...
CVE-2023-0104HIGH7.8 The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious pr...
CVE-2023-0966HIGH8.8A vulnerability classified as problematic was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerab...
CVE-2023-0941HIGH8.8Use after free in Prompts in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap...
CVE-2023-0933HIGH8.8Integer overflow in PDF in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap c...
CVE-2023-0932HIGH8.8Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the...
CVE-2023-0931HIGH8.8Use after free in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap c...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now