2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5819MEDIUM4.8The Amazonify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to...
CVE-2023-5818MEDIUM4.3The Amazonify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8...
CVE-2023-4956MEDIUM4.3A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user in...
CVE-2023-4154MEDIUM6.5A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directo...
CVE-2023-46243HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver...
CVE-2023-37835Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-45396. Reason: This record is a duplicate of CVE-2023-...
CVE-2023-5998HIGH7.5Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV.
CVE-2023-5309CRITICAL9.8Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for...
CVE-2023-46253HIGH7.2Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file wr...
CVE-2023-46252MEDIUM6.1Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in ...
CVE-2023-46244HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver...
CVE-2023-46242HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver...
CVE-2023-46744MEDIUM5.4Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (X...
CVE-2023-46737MEDIUM5.3Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker contro...
CVE-2023-46730HIGH8.8Group-Office is an enterprise CRM and groupware tool. In affected versions there is full Server-Side Request Forgery (SS...
CVE-2023-46501CRITICAL9.1An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view a...
CVE-2023-41798HIGH8.8Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Direct...
CVE-2023-32966MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab Jazz Popups leads to Stored XSS.This issue affects Jazz Popup...
CVE-2023-28499MEDIUM5.4Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML...
CVE-2023-0898HIGH7.3 General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in...
CVE-2023-5179HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat ...
CVE-2023-4295HIGH7.8A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
CVE-2023-4272MEDIUM5.5A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory. ...
CVE-2023-47360HIGH7.5Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.
CVE-2023-47359CRITICAL9.8Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in fun...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now