2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-43740HIGH8.8Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_...
CVE-2023-43013CRITICAL9.8Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter ...
CVE-2023-41911MEDIUM5.5Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2).
CVE-2023-43323MEDIUM6.5mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP a...
CVE-2023-43226HIGH8.8An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute ...
CVE-2023-5256HIGH7.5In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause se...
CVE-2023-43664MEDIUM4.3PrestaShop is an Open Source e-commerce web application. In the Prestashop Back office interface, an employee can list a...
CVE-2023-43663MEDIUM4.3PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled ...
CVE-2023-43657MEDIUM6.1discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encry...
CVE-2023-43044HIGH7.5IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send ...
CVE-2023-40375HIGH7.8Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A m...
CVE-2023-39195Rejected reason: CVE-2023-39195 was found to be a duplicate of CVE-2023-42755. Please see https://access.redhat.com/secu...
CVE-2023-5217HIGH8.8Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remo...
CVE-2023-5187HIGH8.8Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to instal...
CVE-2023-5186HIGH8.8Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to e...
CVE-2023-30415CRITICAL9.8Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the...
CVE-2023-43884MEDIUM5.4A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attacke...
CVE-2023-43879MEDIUM4.8Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafte...
CVE-2023-43878MEDIUM5.4Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via ...
CVE-2023-43876MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary w...
CVE-2023-5215MEDIUM6.5A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-...
CVE-2023-43874MEDIUM5.4Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code ...
CVE-2023-43873MEDIUM5.4A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a c...
CVE-2023-43872MEDIUM5.4A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Sit...
CVE-2023-43871MEDIUM5.4A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scriptin...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now