2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42426MEDIUM6.1Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary co...
CVE-2023-43644CRITICAL9.8Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafte...
CVE-2023-43642HIGH7.5snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream ...
CVE-2023-43458MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrar...
CVE-2023-43319MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arb...
CVE-2023-42817MEDIUM5.4Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from ...
CVE-2023-41871MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Poll Maker Team Poll Maker plugin <= 4.7.0 versions.
CVE-2023-41868MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ram Ratan Maurya, Codestag StagTools plugin <= 2.3.7 versi...
CVE-2023-41867MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AcyMailing Newsletter Team AcyMailing plugin <= 8.6.2 vers...
CVE-2023-41863MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Pepro Dev. Group PeproDev CF7 Database plugin <= 1.7.0 versio...
CVE-2023-40581HIGH7.8yt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp allows the user to provide shell command lines to...
CVE-2023-39640CRITICAL9.8UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHoo...
CVE-2023-4156HIGH7.1A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be u...
CVE-2023-5166MEDIUM6.5Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desk...
CVE-2023-5165HIGH8.8Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via t...
CVE-2023-5158MEDIUM5.5A flaw was found in vringh_kiov_advance in drivers/vhost/vringh.c in the host side of a virtio ring in the Linux Kernel....
CVE-2023-5156HIGH7.5A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which ...
CVE-2023-4892MEDIUM4.6Teedy v1.11 has a vulnerability in its text editor that allows events to be executed in HTML tags that an attacker coul...
CVE-2023-4631MEDIUM5.3The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of ...
CVE-2023-4549MEDIUM6.1The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For...
CVE-2023-4521CRITICAL9.8The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to p...
CVE-2023-4502MEDIUM4.8The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings,...
CVE-2023-4490CRITICAL9.8The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statem...
CVE-2023-4476MEDIUM6.1The Locatoraid Store Locator WordPress plugin before 3.9.24 does not sanitise and escape the lpr-search parameter before...
CVE-2023-4300HIGH7.2The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now