2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38870CRITICAL9.8A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book ha...
CVE-2023-42222HIGH8.8WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal funct...
CVE-2023-41450HIGH8.8An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to t...
CVE-2023-41447MEDIUM6.1Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-41446MEDIUM6.1Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-41444HIGH7.8An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privile...
CVE-2023-5244MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-43320HIGH8.8An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxm...
CVE-2023-43314HIGH7.5** UNSUPPORTED WHEN ASSIGNED **The buffer overflow vulnerability in the Zyxel PMG2005-T20B firmware version V1.00(ABNK.2...
CVE-2023-43233MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the cms/content/edit component of YZNCMS v1.3.0 allows attackers to...
CVE-2023-43191MEDIUM5.4SpringbootCMS 1.0 foreground message can be embedded malicious code saved in the database. When users browse the comment...
CVE-2023-41453MEDIUM6.1Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-41452HIGH8.8Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary ...
CVE-2023-41451MEDIUM6.1Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-41449CRITICAL9.8An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to t...
CVE-2023-41448MEDIUM6.1Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-41445MEDIUM6.1Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code v...
CVE-2023-44080CRITICAL9.8An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request...
CVE-2023-43660HIGH8.1Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verif...
CVE-2023-43192HIGH8.8SQL injection can exist in a newly created part of the SpringbootCMS 1.0 background, and the parameters submitted by use...
CVE-2023-4066MEDIUM5.5A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, de...
CVE-2023-43656CRITICAL9matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that ...
CVE-2023-43651CRITICAL9.9JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to exec...
CVE-2023-42818CRITICAL9.8JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH s...
CVE-2023-40026MEDIUM4.3Argo CD is a declarative continuous deployment framework for Kubernetes. In Argo CD versions prior to 2.3 (starting at l...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now