2023 CVE Vulnerabilities

31,399 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45646MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Henryholtgeerts PDF Block plugin <= 1.1.0 versio...
CVE-2023-45644MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anurag Deshmukh CPT Shortcode Generator plugin <= 1.0 ...
CVE-2023-45640MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TechnoWich WP ULike – Most Advanced WordPress Ma...
CVE-2023-45637MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime EventPrime – Events Calendar, Bookings and Tick...
CVE-2023-45634MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Biztechc Copy or Move Comments plugin <= 5.0.4 versions.
CVE-2023-45555HIGH7.8File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the...
CVE-2023-45554CRITICAL9.8File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the i...
CVE-2023-45321HIGH8.8The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address...
CVE-2023-45220HIGH8.8The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address),...
CVE-2023-44794CRITICAL9.8An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payl...
CVE-2023-44769MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code ...
CVE-2023-44767MEDIUM4.8A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.
CVE-2023-43961HIGH8.8An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted reque...
CVE-2023-43795CRITICAL9.8GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC...
CVE-2023-43510MEDIUM6.3A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run ...
CVE-2023-43509MEDIUM5.8A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote ...
CVE-2023-43508MEDIUM6.5Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privi...
CVE-2023-43507HIGH8.8A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote at...
CVE-2023-43506HIGH7.8A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their us...
CVE-2023-43488HIGH7.8The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be d...
CVE-2023-43360MEDIUM5.4Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a cra...
CVE-2023-43281MEDIUM6.5Double Free vulnerability in Nothings Stb Image.h v.2.28 allows a remote attacker to cause a denial of service via a cra...
CVE-2023-42494CRITICAL9.8 EisBaer Scada - CWE-749: Exposed Dangerous Method or Function
CVE-2023-42493CRITICAL9.8 EisBaer Scada - CWE-256: Plaintext Storage of a Password
CVE-2023-42492CRITICAL9.8 EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now