2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2188MEDIUM4.9The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and...
CVE-2023-2174MEDIUM4.3The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2023-2173MEDIUM4.3The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7...
CVE-2023-2172MEDIUM4.3The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7...
CVE-2023-2171MEDIUM5.4The BadgeOS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions ...
CVE-2023-0689MEDIUM4.3The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name'...
CVE-2023-4655MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1.
CVE-2023-4654LOW3.5Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1.
CVE-2023-4653MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-4652MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-4651MEDIUM5.4Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1.
CVE-2023-4650MEDIUM4.7Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
CVE-2023-4649MEDIUM5.4Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1.
CVE-2023-4163MEDIUM4.4In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, le...
CVE-2023-4162MEDIUM4.4A segmentation fault can occur in Brocade Fabric OS after Brocade Fabric OS v9.0 and before Brocade Fabric OS v9.2.0a ...
CVE-2023-31925MEDIUM6.5Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A privileged user could ...
CVE-2023-31424CRITICAL9.8Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web...
CVE-2023-31423MEDIUM5.5Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration ...
CVE-2023-3489HIGH7.5The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in t...
CVE-2023-23765MEDIUM6.5An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displa...
CVE-2023-41163MEDIUM6.1A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to...
CVE-2023-41041LOW3.1Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged ...
CVE-2023-41040MEDIUM6.5GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython...
CVE-2023-39139HIGH7.8An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
CVE-2023-39138HIGH7.8An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now