2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-44846HIGH8.8An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component.
CVE-2023-5463HIGH7.8A vulnerability was found in XINJE XDPPro up to 3.7.17a. It has been rated as critical. Affected by this issue is some u...
CVE-2023-5462HIGH7.5A vulnerability was found in XINJE XD5E-30R-E 3.5.3b. It has been declared as critical. Affected by this vulnerability i...
CVE-2023-43899CRITICAL9.8hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx.
CVE-2023-43641HIGH8.8libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-o...
CVE-2023-44813MEDIUM6.1Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a c...
CVE-2023-44812MEDIUM6.1Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a c...
CVE-2023-43271CRITICAL9.1Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the d...
CVE-2023-5461MEDIUM5.9A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unkno...
CVE-2023-44821MEDIUM5.5Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denia...
CVE-2023-44811HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in MooSocial v.3.1.8 allows a remote attacker to execute arbitrary code ...
CVE-2023-44467CRITICAL9.8langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-202...
CVE-2023-44392CRITICAL9Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a d...
CVE-2023-5460MEDIUM5.7A vulnerability was found in Delta Electronics WPLSoft up to 2.51 and classified as problematic. This issue affects some...
CVE-2023-5459HIGH7.5A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability aff...
CVE-2023-41672HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Rémi Leclercq Hide admin notices – Admin Notification Center plugin <...
CVE-2023-41670HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Palasthotel (in person: Edward Bock) Use Memcached plugin <= 1.0.4 ve...
CVE-2023-41669HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Live News plugin <= 1.06 versions.
CVE-2023-41668HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Leadster plugin <= 1.1.2 versions.
CVE-2023-41667HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions.
CVE-2023-39194MEDIUM4.4A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filt...
CVE-2023-39193MEDIUM6A flaw was found in the Netfilter subsystem in the Linux kernel. The sctp_mt_check did not validate the flag_count field...
CVE-2023-39192MEDIUM6A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt...
CVE-2023-39189MEDIUM6A flaw was found in the Netfilter subsystem in the Linux kernel. The nfnl_osf_add_callback function did not validate the...
CVE-2023-42455HIGH8.8Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possib...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now