2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-47532MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themeum WP Crowdfunding plugin <= 2.1.6 versions.
CVE-2023-47528MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sajjad Hossain Sagor WP Edit Username plugin <= 1.0.5 ...
CVE-2023-47524MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability (requires PHP 8.x) in CodeBard CodeBard's Patron Button and W...
CVE-2023-47522MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Feed plugin <= 2.2.1 versions.
CVE-2023-47520MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Uno (miunosoft) Responsive Column Widgets plugin <...
CVE-2023-46582HIGH7.8SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary SQL commands via ...
CVE-2023-46581MEDIUM5.5SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name...
CVE-2023-46580MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the...
CVE-2023-46026MEDIUM4.8Cross Site Scripting (XSS) vulnerability in profile.php in phpgurukul Teacher Subject Allocation Management System 1.0 a...
CVE-2023-46025MEDIUM4.9SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows at...
CVE-2023-46024HIGH7.5SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers...
CVE-2023-46023MEDIUM6.5SQL injection vulnerability in addTask.php in Code-Projects Simple Task List 1.0 allows attackers to obtain sensitive in...
CVE-2023-46022HIGH7.8SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands...
CVE-2023-39537HIGH7.8AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network...
CVE-2023-39536HIGH7.8AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network...
CVE-2023-39535HIGH7.8AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper input validation via the local network...
CVE-2023-36558MEDIUM5.5ASP.NET Core Security Feature Bypass Vulnerability
CVE-2023-36038HIGH7.5ASP.NET Core Denial of Service Vulnerability
CVE-2023-5528HIGH8.8A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes ...
CVE-2023-47641MEDIUM6.5aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a secu...
CVE-2023-47640HIGH8.8DataHub is an open-source metadata platform. The HMAC signature for DataHub Frontend sessions was being signed using a S...
CVE-2023-47631HIGH8.8vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party...
CVE-2023-47630HIGH7.1Kyverno is a policy engine designed for Kubernetes. An issue was found in Kyverno that allowed an attacker to control th...
CVE-2023-47627HIGH7.5aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous ...
CVE-2023-47549MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now