2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-23369CRITICAL9.8An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2023-23368CRITICAL9.8An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2023-46980CRITICAL9.8An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privile...
CVE-2023-46404CRITICAL9.9PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping ...
CVE-2023-5946MEDIUM6.1The Digirisk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_group_id' parameter i...
CVE-2023-5088HIGH7A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset...
CVE-2023-5945MEDIUM5.4The video carousel slider with lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0....
CVE-2023-5707MEDIUM5.4The SEO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slider' shortcode and...
CVE-2023-46947HIGH8.8Subrion 4.2.1 has a remote command execution vulnerability in the backend.
CVE-2023-3961CRITICAL9.8A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain socke...
CVE-2023-26015CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson M...
CVE-2023-25960CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – ...
CVE-2023-4592MEDIUM6.1A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability...
CVE-2023-4591CRITICAL9.8A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an ...
CVE-2023-41652CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVP...
CVE-2023-3277CRITICAL9.8The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up...
CVE-2023-34383CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project ...
CVE-2023-4769HIGH8.8A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfi...
CVE-2023-4768MEDIUM6.1A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerabilit...
CVE-2023-4767MEDIUM6.1A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerabilit...
CVE-2023-4043HIGH7.5In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exp...
CVE-2023-1476HIGH7A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue ...
CVE-2023-5824HIGH7.5A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. Howeve...
CVE-2023-4091MEDIUM6.5A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permis...
CVE-2023-46848HIGH7.5Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Reques...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now