2023 CVE Vulnerabilities

31,400 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-35181HIGH7.8The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows us...
CVE-2023-35180HIGH8.8The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows a...
CVE-2023-31046MEDIUM6.5A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditi...
CVE-2023-45883HIGH7.8A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a sta...
CVE-2023-45384CRITICAL9.8KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the modu...
CVE-2023-45379CRITICAL9.8In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from PosThemes for PrestaShop, a guest can pe...
CVE-2023-43252HIGH7.8XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.
CVE-2023-46227HIGH7.5 Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache...
CVE-2023-25753MEDIUM6.5 There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vu...
CVE-2023-34050MEDIUM4.3 In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class na...
CVE-2023-5254MEDIUM5.3The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9...
CVE-2023-5241HIGH8.1The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9...
CVE-2023-5212HIGH8.1The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as ...
CVE-2023-5204HIGH7.5The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and includin...
CVE-2023-46229HIGH8.8LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an e...
CVE-2023-46228HIGH7.8zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, ...
CVE-2023-37503CRITICAL9.8HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access...
CVE-2023-5639MEDIUM5.4The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tmfshortcode' shor...
CVE-2023-5638MEDIUM5.4The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcj_image' shortcode ...
CVE-2023-5336MEDIUM6.5The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's ...
CVE-2023-4645MEDIUM5.3The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 v...
CVE-2023-37504MEDIUM6.5HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions ...
CVE-2023-36857MEDIUM6.5 Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a replay vulnerability which could allo...
CVE-2023-34441HIGH8.2 Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a cleartext transmission vulnerability ...
CVE-2023-34437HIGH7.5Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieva...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now