2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45387CRITICAL9.8In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModul...
CVE-2023-45382HIGH7.5In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can downl...
CVE-2023-48078CRITICAL9.8SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands ...
CVE-2023-48237MEDIUM4.3Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and us...
CVE-2023-48236MEDIUM4.3Vim is an open source command line text editor. When using the z= command, the user may overflow the count with values l...
CVE-2023-48235MEDIUM4.3Vim is an open source command line text editor. When parsing relative ex addresses one may unintentionally cause an over...
CVE-2023-48234MEDIUM4.3Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for ...
CVE-2023-48233MEDIUM4.3Vim is an open source command line text editor. If the count after the :s command is larger than what fits into a (signe...
CVE-2023-48232MEDIUM4.3Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset fo...
CVE-2023-48231MEDIUM4.3Vim is an open source command line text editor. When closing a window, vim may try to access already freed window struct...
CVE-2023-47687HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in VJInfotech Woo Custom and Sequential Order Number plugin <= 2.6.0 ver...
CVE-2023-47686HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.2.2 ve...
CVE-2023-47025MEDIUM5.5An issue in Free5gc v.3.3.0 allows a local attacker to cause a denial of service via the free5gc-compose component.
CVE-2023-48222MEDIUM5.4Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions a...
CVE-2023-47688HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Alexufo Youtube SpeedLoad plugin <= 0.6.3 versions.
CVE-2023-47642MEDIUM4.3Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who h...
CVE-2023-47112MEDIUM4.3Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions a...
CVE-2023-40314MEDIUM6.1 Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian and Horizon allows an attacker access ...
CVE-2023-6020HIGH7.5LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
CVE-2023-6014CRITICAL9.8An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
CVE-2023-46214HIGH8.8In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet la...
CVE-2023-46213MEDIUM4.8In Splunk Enterprise versions below 9.0.7 and 9.1.2, ineffective escaping in the “Show syntax Highlighted” feature can r...
CVE-2023-39926MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Acurax Under Construction / Maintenance Mode from Acurax plug...
CVE-2023-36026MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2023-36008MEDIUM6.6Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now