2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38558MEDIUM5.5A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Ad...
CVE-2023-38557HIGH7.8A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper ac...
CVE-2023-4516HIGH7.8 A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allo...
CVE-2023-42503MEDIUM5.5Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.Thi...
CVE-2023-41267HIGH7.8In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect...
CVE-2023-38206MEDIUM5.3Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improp...
CVE-2023-38205HIGH7.5Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improp...
CVE-2023-38204CRITICAL9.8Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deseria...
CVE-2023-4814HIGH7.1 A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete a...
CVE-2023-26141MEDIUM4.9Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the...
CVE-2023-4948MEDIUM4.3The WooCommerce CVR Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2023-4945MEDIUM5.4The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in...
CVE-2023-4944MEDIUM5.4The Awesome Weather Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' short...
CVE-2023-4841MEDIUM5.4The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in ...
CVE-2023-23845HIGH7.2The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ...
CVE-2023-23840HIGH7.2The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ...
CVE-2023-41162MEDIUM6.1A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to...
CVE-2023-41158MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers...
CVE-2023-41155MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the mail forwarding and replies tab in Webmin and Usermin 2.000 all...
CVE-2023-41154MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the scheduled cron jobs tab in Usermin 2.000 allows remote attacker...
CVE-2023-41152MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers...
CVE-2023-40617MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execut...
CVE-2023-4568MEDIUM6.5PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to...
CVE-2023-42468MEDIUM5.3The com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls ...
CVE-2023-41892CRITICAL9.8Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users run...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now