2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41948MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christoph Rado Cookie Notice & Consent plugin <= 1.6.0...
CVE-2023-41874MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce plugin...
CVE-2023-5146HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231 and classified ...
CVE-2023-5145HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-7000 up to 20151231 and classified as criti...
CVE-2023-5144HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-7000 and DAR-...
CVE-2023-5143CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000 up ...
CVE-2023-5142MEDIUM5.3A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, ...
CVE-2023-1636MEDIUM5A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that ut...
CVE-2023-1633MEDIUM5.5A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the con...
CVE-2023-1625MEDIUM5An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the...
CVE-2023-1260HIGH8An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated ...
CVE-2023-5134MEDIUM4.3The Easy Registration Forms for WordPress is vulnerable to Information Disclosure via the 'erforms_user_meta' shortcode ...
CVE-2023-5125MEDIUM5.4The Contact Form by FormGet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formget' shortcode in...
CVE-2023-43470CRITICAL9.8SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via ...
CVE-2023-43469CRITICAL9.8SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via th...
CVE-2023-43468CRITICAL9.8SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via th...
CVE-2023-43338CRITICAL9.8Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr()....
CVE-2023-43130CRITICAL9.8D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection.
CVE-2023-43129CRITICAL9.8D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of ...
CVE-2023-40989CRITICAL9.8SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code ...
CVE-2023-43270CRITICAL9.8dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /h...
CVE-2023-38346HIGH8.8An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and ...
CVE-2023-43640MEDIUM6.5TaxonWorks is a web-based workbench designed for taxonomists and biodiversity scientists. Prior to version 0.34.0, a SQL...
CVE-2023-42821HIGH7.5The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to p...
CVE-2023-42812MEDIUM4.3Galaxy is an open-source platform for FAIR data analysis. Prior to version 22.05, Galaxy is vulnerable to server-side re...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now