2023 CVE Vulnerabilities

31,401 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-44998HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in josecoelho, Randy Hoyt, steveclarkcouk, Vitaliy Kukin, Eric Le Bail, ...
CVE-2023-5046CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology ...
CVE-2023-5045CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology ...
CVE-2023-43789MEDIUM5.5A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a local user can trigger a...
CVE-2023-23737CRITICAL9.8Unauth. SQL Injection (SQLi) vulnerability in MainWP MainWP Broken Links Checker Extension plugin <= 4.0 versions.
CVE-2023-23651HIGH8.8Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions.
CVE-2023-5556MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository structurizr/onpremises prior to 3194.
CVE-2023-5555MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4.
CVE-2023-5554CRITICAL9.8Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16...
CVE-2023-45047HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions.
CVE-2023-5470MEDIUM5.4The Etsy Shop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etsy-shop' shortcode in versions up...
CVE-2023-32724HIGH8.8Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory ...
CVE-2023-32723CRITICAL9.1Request to LDAP is sent before user permissions are checked.
CVE-2023-32722HIGH7.8The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.
CVE-2023-32721MEDIUM5.4A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before U...
CVE-2023-5531MEDIUM4.3The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a...
CVE-2023-40833CRITICAL9.8An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSe...
CVE-2023-29453CRITICAL9.8Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Ba...
CVE-2023-44793Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-40829HIGH7.5There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5...
CVE-2023-42298MEDIUM5.5An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSp...
CVE-2023-1943HIGH8.8Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.
CVE-2023-5487MEDIUM6.5Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a u...
CVE-2023-5486MEDIUM4.3Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof securit...
CVE-2023-5485MEDIUM4.3Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass aut...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now