2023 CVE Vulnerabilities

31,401 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42629MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, ...
CVE-2023-24385MEDIUM4.8Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in David Lingren Media Library Assistant plugin <= 3.11 ...
CVE-2023-4399HIGH7.2Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny...
CVE-2023-42497MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through ...
CVE-2023-4089LOW2.7On affected Wago products an remote attacker with administrative privileges can access files to which he has already acc...
CVE-2023-41752HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apa...
CVE-2023-39456HIGH7.5Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache ...
CVE-2023-44694CRITICAL9.8D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /log/mailrecvview.php.
CVE-2023-44693CRITICAL9.8D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php.
CVE-2023-45386CRITICAL9.8In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via `...
CVE-2023-45375HIGH8.8In the module "PireosPay" (pireospay) before version 1.7.10 from 01generator.com for PrestaShop, a guest can perform SQL...
CVE-2023-45358MEDIUM5.4Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote...
CVE-2023-45357MEDIUM6.5Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authen...
CVE-2023-34210HIGH8.8SQL Injection in create customer group function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticat...
CVE-2023-34209MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere in create template function in EasyUse MailHu...
CVE-2023-34208MEDIUM6.5Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated us...
CVE-2023-34207HIGH8.8Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate...
CVE-2023-4215HIGH7.5Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability t...
CVE-2023-45659LOW2.8Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained acc...
CVE-2023-45152LOW2.3Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it po...
CVE-2023-40373HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially cr...
CVE-2023-40372HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special...
CVE-2023-38719MEDIUM4.4IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation ...
CVE-2023-40374HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special...
CVE-2023-30991HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now