2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5381MEDIUM4.8The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ver...
CVE-2023-4723MEDIUM5.3The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and...
CVE-2023-4690MEDIUM4.3The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc...
CVE-2023-4689MEDIUM4.3The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc...
CVE-2023-48200MEDIUM5.4Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensiti...
CVE-2023-48199HIGH7.8HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTM...
CVE-2023-48198MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy ...
CVE-2023-48197MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to...
CVE-2023-48365CRITICAL9.9Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683....
CVE-2023-47444HIGH8.8An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privi...
CVE-2023-47347HIGH7.5Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages w...
CVE-2023-47345HIGH7.5Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message wi...
CVE-2023-41442CRITICAL9.8An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute...
CVE-2023-6105MEDIUM5.5An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys bein...
CVE-2023-48224CRITICAL9.1Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime ...
CVE-2023-47638Rejected reason: Confirm reference is not public.
CVE-2023-47637HIGH8.8Pimcore is an Open Source Data & Experience Management Platform. In affected versions the `/admin/object/grid-proxy` end...
CVE-2023-47636MEDIUM5.3The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable th...
CVE-2023-41699MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (...
CVE-2023-30954LOW3.7The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls ne...
CVE-2023-22818HIGH7.8Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could...
CVE-2023-48219MEDIUM6.1TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyM...
CVE-2023-48014HIGH7.8GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a stack overflow via the hevc_parse_vps_extension funct...
CVE-2023-48013HIGH7.8GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at /...
CVE-2023-48011HIGH7.8GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a heap-use-after-free via the flush_ref_samples functio...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now