2023 CVE Vulnerabilities

31,401 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-5582MEDIUM5.4A vulnerability, which was classified as problematic, has been found in ZZZCMS 2.2.0. This issue affects some unknown pr...
CVE-2023-5581MEDIUM6.1A vulnerability classified as problematic was found in SourceCodester Medicine Tracker System 1.0. This vulnerability af...
CVE-2023-5580CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Library System 1.0. This affects an unknown part...
CVE-2023-5579MEDIUM6.5A vulnerability was found in yhz66 Sandbox 6.1.0. It has been rated as problematic. Affected by this issue is some unkno...
CVE-2023-1259MEDIUM5.5The Hotjar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the hotjar_site_id in versions up to, a...
CVE-2023-5578MEDIUM5.4A vulnerability was found in Portábilis i-Educar up to 2.7.5. It has been declared as problematic. Affected by this vuln...
CVE-2023-45348MEDIUM4.3Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve s...
CVE-2023-42792MEDIUM6.5Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with lim...
CVE-2023-42780MEDIUM6.5Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to...
CVE-2023-42663MEDIUM6.5Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specifi...
CVE-2023-45856CRITICAL9.8qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the ...
CVE-2023-45855HIGH7.5qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
CVE-2023-44037HIGH7.5An issue in ZPE Systems, Inc Nodegrid OS v.5.8.10 thru v.5.8.13 and v.5.10.3 thru v.5.10.5 allows a remote attacker to o...
CVE-2023-26155CRITICAL9.8All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt(...
CVE-2023-30154CRITICAL9.8Multiple improper neutralization of SQL parameters in module AfterMail (aftermailpresta) for PrestaShop, before version ...
CVE-2023-30148MEDIUM5.4Multiple Stored Cross Site Scripting (XSS) vulnerabilities in Opart opartmultihtmlblock before version 2.0.12 and Opart ...
CVE-2023-45853CRITICAL9.8MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 ...
CVE-2023-45852CRITICAL9.8In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute a...
CVE-2023-45674MEDIUM6.5Farmbot-Web-App is a web control interface for the Farmbot farm automation platform. An SQL injection vulnerability was ...
CVE-2023-4257CRITICAL9.8Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.
CVE-2023-4263HIGH8.8Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driver
CVE-2023-36559MEDIUM4.2Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2023-34977MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability co...
CVE-2023-34976HIGH8.8A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow aut...
CVE-2023-34975HIGH8.8An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now