2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-44008CRITICAL9.8File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manage...
CVE-2023-43836MEDIUM6.5There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information
CVE-2023-43361HIGH7.8Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a deni...
CVE-2023-43297MEDIUM5.4An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access toke...
CVE-2023-43268HIGH8.8Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.
CVE-2023-43267MEDIUM5.4A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to exec...
CVE-2023-5344HIGH7.5Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
CVE-2023-44463MEDIUM5.3An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to tr...
CVE-2023-43890HIGH8.8Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vu...
CVE-2023-43835HIGH8.8Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote C...
CVE-2023-3592HIGH7.5In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains ...
CVE-2023-37605MEDIUM5.5Weak Exception Handling vulnerability in baramundi software GmbH EMM Agent 23.1.50 and before allows an attacker to caus...
CVE-2023-0809MEDIUM5.3In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packet...
CVE-2023-40744Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2023-5290Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-4659CRITICAL9.8Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the...
CVE-2023-3770MEDIUM4.3  Incorrect validation vulnerability of the data entered, allowing an attacker with access to the network on which the a...
CVE-2023-3769HIGH7.5Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuz...
CVE-2023-3744HIGH8.8Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attack...
CVE-2023-41580HIGH7.5Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-sear...
CVE-2023-5106HIGH7.5An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3....
CVE-2023-5160MEDIUM4.3Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a me...
CVE-2023-44266MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jewel Theme WP Adminify plugin <= 3.1.6 versions.
CVE-2023-44265MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Popup contact form plugin <= 7.1 version...
CVE-2023-44264MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plu...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now