2023 CVE Vulnerabilities

31,400 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-46298HIGH7.5Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached ...
CVE-2023-38735MEDIUM6.5IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused ...
CVE-2023-38276HIGH7.5IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid...
CVE-2023-38275HIGH7.5IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to ...
CVE-2023-46078HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in PluginEver WC Serial Numbers plugin <= 1.6.3 versions.
CVE-2023-46067HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Qwerty23 Rocket Font plugin <= 1.2.3 versions.
CVE-2023-5205MEDIUM5.4The Add Custom Body Class plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_custom_body_cla...
CVE-2023-4939MEDIUM5.3The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due...
CVE-2023-4635MEDIUM6.1The EventON plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up ...
CVE-2023-5684CRITICAL9.8A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012. It has been declared as critical. Aff...
CVE-2023-46055HIGH8.8An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a cra...
CVE-2023-46054MEDIUM5.4Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges ...
CVE-2023-5683CRITICAL9.8A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231010 and classified as critical. This issue...
CVE-2023-5132HIGH7.5The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit...
CVE-2023-46003MEDIUM5.4I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.
CVE-2023-38194MEDIUM6.1An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.
CVE-2023-38193HIGH8.8An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command l...
CVE-2023-38192MEDIUM6.1An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwor...
CVE-2023-38190HIGH8.8An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.
CVE-2023-45682HIGH7.1stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of boun...
CVE-2023-45681HIGH7.8stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory writ...
CVE-2023-45680MEDIUM5.5stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allo...
CVE-2023-45679HIGH7.8stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allo...
CVE-2023-45678HIGH7.8stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of buff...
CVE-2023-45677HIGH7.8stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of boun...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now