2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6112HIGH8.8Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit h...
CVE-2023-5997HIGH8.8Use after free in Garbage Collection in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially e...
CVE-2023-6079Rejected reason: appears to be a duplicate of CVE-2023-40206
CVE-2023-34982HIGH7.1 This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges t...
CVE-2023-33873HIGH7.8 This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileg...
CVE-2023-48089HIGH8.8xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.
CVE-2023-48088MEDIUM5.4xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage.
CVE-2023-48087MEDIUM5.4xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/l...
CVE-2023-5720HIGH7.5A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing cer...
CVE-2023-5676MEDIUM5.9In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentatio...
CVE-2023-5245CRITICAL9.8FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the a...
CVE-2023-4602MEDIUM6.1The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in ...
CVE-2023-23549LOW2.7Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial deni...
CVE-2023-34062HIGH7.5In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can se...
CVE-2023-46672MEDIUM5.5An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstanc...
CVE-2023-6133MEDIUM4.9The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'for...
CVE-2023-4889MEDIUM5.4The Shareaholic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shareaholic' shortcode in version...
CVE-2023-47586HIGH7.8Multiple heap-based buffer overflow vulnerabilities exist in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 ...
CVE-2023-47585HIGH7.8Out-of-bounds read vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a ...
CVE-2023-47584HIGH7.8Out-of-bounds write vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a...
CVE-2023-47583HIGH7.8Multiple out-of-bounds read vulnerabilities exist in TELLUS Simulator V4.0.17.0 and earlier. If a user opens a specially...
CVE-2023-47582HIGH7.8Access of uninitialized pointer vulnerability exists in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earli...
CVE-2023-47581HIGH7.8Out-of-bounds read vulnerability exists in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user...
CVE-2023-47580HIGH7.8Multiple improper restriction of operations within the bounds of a memory buffer issues exist in TELLUS V4.0.17.0 and ea...
CVE-2023-47446MEDIUM5.4Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname param...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now