2023 CVE Vulnerabilities

31,400 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-43344MEDIUM5.4Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary co...
CVE-2023-43342MEDIUM5.4Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary co...
CVE-2023-43341MEDIUM6.1Cross-site scripting (XSS) vulnerability in evolution evo v.3.2.3 allows a local attacker to execute arbitrary code via ...
CVE-2023-45823HIGH7.5Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for...
CVE-2023-45822MEDIUM5.3Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for...
CVE-2023-45821MEDIUM6.3Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for...
CVE-2023-30132HIGH7.8An issue discovered in IXP Data EasyInstall 6.6.14907.0 allows attackers to gain escalated privileges via static Cryptog...
CVE-2023-30131CRITICAL9.8An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege,...
CVE-2023-27795HIGH7.8An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key.
CVE-2023-27793HIGH7.8An issue discovered in IXP Data Easy Install v.6.6.14884.0 allows local attackers to gain escalated privileges via weak ...
CVE-2023-27792HIGH7.8An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions ...
CVE-2023-45376CRITICAL9.8In the module "Carousels Pack - Instagram, Products, Brands, Supplier" (hicarouselspack) for PrestaShop up to version 1....
CVE-2023-43492CRITICAL9.8 In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which ...
CVE-2023-40145HIGH8.8 In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to th...
CVE-2023-38584CRITICAL9.8 In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which...
CVE-2023-30633MEDIUM5.3An issue was discovered in TrEEConfigDriver in Insyde InsydeH2O with kernel 5.0 through 5.5. It can report false TPM PCR...
CVE-2023-27791HIGH8.1An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG.
CVE-2023-45992CRITICAL9.6A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could...
CVE-2023-45826MEDIUM6.5Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files....
CVE-2023-45825MEDIUM5.5ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custo...
CVE-2023-45820MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus insta...
CVE-2023-45809LOW2.7Wagtail is an open source content management system built on Django. A user with a limited-permission editor account for...
CVE-2023-45381CRITICAL9.8In the module "Creative Popup" (creativepopup) up to version 1.6.9 from WebshopWorks for PrestaShop, a guest can perform...
CVE-2023-43986CRITICAL9.8DM Concept configurator before v4.9.4 was discovered to contain a SQL injection vulnerability via the component Configur...
CVE-2023-42666MEDIUM5.3 The affected product is vulnerable to an exposure of sensitive information to an unauthorized actor vulnera...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now