2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-47109HIGH8.1PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that t...
CVE-2023-43570MEDIUM6.7 A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacke...
CVE-2023-43569MEDIUM6.7A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with...
CVE-2023-43568MEDIUM4.4A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a loc...
CVE-2023-43567MEDIUM6.7A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a loca...
CVE-2023-36667HIGH7.5Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.
CVE-2023-46363MEDIUM5.5jbig2enc v0.28 was discovered to contain a SEGV via jbig2_add_page in src/jbig2enc.cc:512.
CVE-2023-46362MEDIUM5.5jbig2enc v0.28 was discovered to contain a heap-use-after-free via jbig2enc_auto_threshold_using_hash in src/jbig2enc.cc...
CVE-2023-45875HIGH7.5An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node ...
CVE-2023-45857MEDIUM6.5An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it i...
CVE-2023-29974CRITICAL9.8An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requireme...
CVE-2023-0392MEDIUM6.7The LDAP Agent Update service with versions prior to 5.18 used an unquoted path, which could allow arbitrary code execut...
CVE-2023-5996HIGH8.8Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit hea...
CVE-2023-26221LOW3.9The Spotfire Connectors component of TIBCO Software Inc.'s Spotfire Analyst, Spotfire Server, and Spotfire for AWS Marke...
CVE-2023-47231MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 version...
CVE-2023-47229MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Vyas Dipen Top 25 Social Icons plugin <= 3.1 ver...
CVE-2023-47228MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions.
CVE-2023-47227MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Social Feed | All social media in one plac...
CVE-2023-47226MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Post Sliders & Post Grids plug...
CVE-2023-47223MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Map Plugins Basic Interactive World Map plugin <= 2...
CVE-2023-47190MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Apollo13Themes Apollo13 Framework Extensions plu...
CVE-2023-47181MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson IdeaPush plugin <= 8.52 versions.
CVE-2023-3282MEDIUM6.7A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linu...
CVE-2023-5913CRITICAL9.8Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited ...
CVE-2023-5760HIGH7A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now