2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40407HIGH7.5The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. A remote attacker may be ab...
CVE-2023-40406MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, macOS Ventura 13.6, macOS Sono...
CVE-2023-40403MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and ...
CVE-2023-40402MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. An app may be ab...
CVE-2023-40400CRITICAL9.8This issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS S...
CVE-2023-40399MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10,...
CVE-2023-40395LOW3.3The issue was addressed with improved handling of caches. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, macO...
CVE-2023-40391MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonom...
CVE-2023-40388MEDIUM4.3A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. Safari ...
CVE-2023-40386LOW3.3A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app ...
CVE-2023-40384LOW3.3A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in tvOS 17, iOS ...
CVE-2023-40333MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Qode Interactive Bridge Core plugin <= 3.0.9 versions.
CVE-2023-40330MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Milan Petrovic GD Security Headers plugin <= 1.6.1 version...
CVE-2023-40219HIGH7.2Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to a...
CVE-2023-40049MEDIUM5.3 In WS_FTP Server version prior to 8.8.2, an unauthenticated user could enumerate files under the 'WebServiceHost' d...
CVE-2023-40048MEDIUM6.5 In WS_FTP Server version prior to 8.8.2, the WS_FTP Server Manager interface was missing cross-site request forgery...
CVE-2023-40047MEDIUM4.8 In WS_FTP Server version prior to 8.8.2, a stored cross-site scripting (XSS) vulnerability exists in WS_FTP Server's ...
CVE-2023-40046HIGH7.2 In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a SQL injection vulnerability exists in the WS_FTP Server manag...
CVE-2023-40045MEDIUM6.1 In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a reflected cross-site scripting (XSS) vulnerability exists in ...
CVE-2023-40044HIGH8.8In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization v...
CVE-2023-3767CRITICAL9.8An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability co...
CVE-2023-3223HIGH7.5A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multip...
CVE-2023-39434HIGH8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, watch...
CVE-2023-39378HIGH8.8 SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') by an unaut...
CVE-2023-39377HIGH7.2 SiberianCMS - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privilege...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now