2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-46239HIGH7.5quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by seri...
CVE-2023-46993CRITICAL9.8In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable ...
CVE-2023-46992HIGH7.5TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral ...
CVE-2023-46237MEDIUM5.3FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint...
CVE-2023-46236HIGH7.5FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-si...
CVE-2023-46235MEDIUM6.1FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10.15, due to a...
CVE-2023-42658HIGH7.8 Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profi...
CVE-2023-42425CRITICAL9.8An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensit...
CVE-2023-40050HIGH8.8Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec...
CVE-2023-37966CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech Us...
CVE-2023-37243HIGH7.8The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM w...
CVE-2023-36508CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contac...
CVE-2023-35879CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Produc...
CVE-2023-33927CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple...
CVE-2023-31212CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database...
CVE-2023-24410CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPM...
CVE-2023-22518CRITICAL9.8All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz...
CVE-2023-5519MEDIUM4.3The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attacke...
CVE-2023-5458MEDIUM5.4The CITS Support svg, webp Media and TTF,OTF File Upload WordPress plugin before 3.0 does not sanitise uploaded SVG file...
CVE-2023-5360CRITICAL9.8The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which...
CVE-2023-5307MEDIUM6.1The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, whic...
CVE-2023-5243MEDIUM4.8The Login Screen Manager WordPress plugin through 3.5.2 does not sanitize and escape some of its settings, which could a...
CVE-2023-5238MEDIUM6.1The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2023-5237MEDIUM5.4The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes be...
CVE-2023-5229MEDIUM4.8The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high priv...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now