2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40931MEDIUM6.5A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers...
CVE-2023-4376MEDIUM4.8The Serial Codes Generator and Validator with WooCommerce Support WordPress plugin before 2.4.15 does not sanitise and e...
CVE-2023-2995MEDIUM4.8The Leyka WordPress plugin before 3.30.4 does not sanitise and escape some of its settings, which could allow high privi...
CVE-2023-43566MEDIUM5.4In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
CVE-2023-42793CRITICAL9.8In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
CVE-2023-22513HIGH8.8This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center an...
CVE-2023-42452MEDIUM5.4Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.x branch prior to versi...
CVE-2023-42451HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and...
CVE-2023-42450HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 4.2.0-beta1 and prior to...
CVE-2023-38356HIGH8.1MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code...
CVE-2023-38355HIGH8.1MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code executio...
CVE-2023-38354HIGH8.1MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code...
CVE-2023-38353MEDIUM5.9MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to...
CVE-2023-38352HIGH8.1MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execut...
CVE-2023-38351HIGH8.1MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code ...
CVE-2023-32182HIGH7.8A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 ...
CVE-2023-42447HIGH7.5blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turne...
CVE-2023-42444HIGH7.5phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8....
CVE-2023-41890HIGH7.5Sustainsys.Saml2 library adds SAML2P support to ASP.NET web sites, allowing the web site to act as a SAML2 Service Provi...
CVE-2023-3892HIGH7.4Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modul...
CVE-2023-4096HIGH8.2Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow ...
CVE-2023-4095MEDIUM5.3User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an a...
CVE-2023-4094HIGH8.2ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests...
CVE-2023-4093MEDIUM6.1Reflected and persistent XSS vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerabil...
CVE-2023-41179HIGH7.2A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now