2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-25488MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Duc Bui Quang WP Default Feature Image plugin <= 1.0.1...
CVE-2023-25477MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Yotuwp Video Gallery plugin <= 1.3.12 versions.
CVE-2023-25044MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions.
CVE-2023-25042MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy (Storm Consultancy) oAuth Twitter Feed for...
CVE-2023-24412MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Web-Settler Image Social Feed plugin <= 1.7.6 versions...
CVE-2023-1555MEDIUM4.3An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting fr...
CVE-2023-1279MEDIUM6.1An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting fro...
CVE-2023-0120MEDIUM4.3An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting fr...
CVE-2023-4704MEDIUM4.9External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-41364CRITICAL9.8In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.
CVE-2023-39685HIGH7.5An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON str...
CVE-2023-24675MEDIUM4.8Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories F...
CVE-2023-24674HIGH7.8Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin p...
CVE-2023-4698HIGH7.5Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.
CVE-2023-4697HIGH8.8Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.
CVE-2023-4696CRITICAL9.8Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
CVE-2023-4695HIGH8.1Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-4481HIGH7.5An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos O...
CVE-2023-39912MEDIUM4.9Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine wh...
CVE-2023-40576HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi...
CVE-2023-40575CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi...
CVE-2023-40574CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi...
CVE-2023-40569CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi...
CVE-2023-40567CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi...
CVE-2023-40188CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now