2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2358MEDIUM4.9 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.5.0.0 and 9.3.0.4, including 8.3.x.x, saves passw...
CVE-2023-2315HIGH8.8Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the ...
CVE-2023-29497LOW3.3A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app ...
CVE-2023-28790MEDIUM4.8Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Brett Shumaker Simple Staff List plugin <= 2.2.3 vers...
CVE-2023-28490MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versio...
CVE-2023-28055HIGH8.8 Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated at...
CVE-2023-27628MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Webvitaly Sitekit plugin <= 1.3 versions.
CVE-2023-27622MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Abel Ruiz GuruWalk Affiliates plugin <= 1.0.0 versions...
CVE-2023-27617MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions.
CVE-2023-27616MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions.
CVE-2023-25483MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ankit Agarwal, Priyanshu Mittal Easy Coming Soon plugi...
CVE-2023-23958MEDIUM6.5Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability.
CVE-2023-23495MEDIUM5.5A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma ...
CVE-2023-0833MEDIUM5.5A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure ...
CVE-2023-0456HIGH7.5A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token fro...
CVE-2023-4259HIGH8.8Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.
CVE-2023-43325MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the data[redirect_url] parameter of mooSocial v3.1.8 allows atta...
CVE-2023-43278HIGH8.8A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an ad...
CVE-2023-38907HIGH7.5An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, a...
CVE-2023-4258MEDIUM6.5In Bluetooth mesh implementation If provisionee has a public key that is sent OOB then during provisioning it can be sen...
CVE-2023-43326MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exisits in multiple url of mooSocial v3.1.8 allows attackers to ste...
CVE-2023-5129Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate of CVE-2023-4863.
CVE-2023-43457CRITICAL9.8An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in...
CVE-2023-43132MEDIUM6.5szvone vmqphp <=1.13 is vulnerable to SQL Injection. Unauthorized remote users can use sql injection attacks to obtain t...
CVE-2023-42753HIGH7.8An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now