2023 CVE Vulnerabilities

31,401 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32976HIGH7.2An OS command injection vulnerability has been reported to affect Container Station. If exploited, the vulnerability cou...
CVE-2023-32974HIGH7.5A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul...
CVE-2023-32973HIGH7.2A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2023-32970MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploite...
CVE-2023-5449LOW3.3A potential security vulnerability has been identified in certain HP Displays supporting the Theft Deterrence feature wh...
CVE-2023-5409MEDIUM6.8HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible t...
CVE-2023-4499HIGH7.5A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and...
CVE-2023-45276HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in automatededitor.Com Automated Editor plugin <= 1.3 versions.
CVE-2023-45270HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.4.0 versions.
CVE-2023-45269MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 2.0.25 versions.
CVE-2023-40682MEDIUM4.4IBM App Connect Enterprise 12.0.1.0 through 12.0.8.0 contains an unspecified vulnerability that could allow a local priv...
CVE-2023-45268HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Hitsteps Hitsteps Web Analytics plugin <= 5.86 versions.
CVE-2023-45267HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Zizou1988 IRivYou plugin <= 2.2.1 versions.
CVE-2023-41843MEDIUM5.4A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa...
CVE-2023-41836MEDIUM6.1An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS...
CVE-2023-41682HIGH7.5A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ...
CVE-2023-41681MEDIUM6.1A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa...
CVE-2023-41680MEDIUM6.1A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa...
CVE-2023-33303HIGH8.1A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthoriz...
CVE-2023-45393MEDIUM6.5An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to a...
CVE-2023-45391MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-...
CVE-2023-45109HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ZAKSTAN WhitePage plugin <= 1.1.5 versions.
CVE-2023-5240HIGH7.5Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with per...
CVE-2023-4995MEDIUM5.4The Embed Calendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'calendly' shortcode in version...
CVE-2023-4829MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now