2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-36076CRITICAL9.8SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and g...
CVE-2023-28366HIGH7.5The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a cli...
CVE-2023-23763MEDIUM5.3An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed ...
CVE-2023-39710MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows atta...
CVE-2023-39703MEDIUM6.1A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute...
CVE-2023-37830MEDIUM6.1A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attacker...
CVE-2023-37829MEDIUM6.1A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attacker...
CVE-2023-37828MEDIUM6.1A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attacker...
CVE-2023-37827MEDIUM6.1A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attacker...
CVE-2023-37826MEDIUM6.1A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attacker...
CVE-2023-37997MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dharmesh Patel Post List With Featured Image plugin <= 1.2...
CVE-2023-37994MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Artem Abramovich Art Decoration Shortcode plugin...
CVE-2023-37986MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange YourMembership Single Sign On – YM SSO Logi...
CVE-2023-37893MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Chop-Chop Coming Soon Chop Chop plugin <= 2.2.4 versions.
CVE-2023-34011MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ShopConstruct plugin <= 1.1.2 versions.
CVE-2023-4647HIGH7.5An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting fr...
CVE-2023-4378MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions start...
CVE-2023-4018MEDIUM5.3An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting fr...
CVE-2023-40970HIGH8.8Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/l...
CVE-2023-40969MEDIUM6.1Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/m...
CVE-2023-40239HIGH7.5Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixe...
CVE-2023-3950LOW3.8An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 ...
CVE-2023-3915HIGH7.2An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting...
CVE-2023-3210MEDIUM6.5An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting f...
CVE-2023-3205MEDIUM6.5An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting f...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now