2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-25019MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premio Chaty plugin <= 3.0.9 versions
CVE-2023-32740MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.8.1 versions.
CVE-2023-3136MEDIUM6.1The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up t...
CVE-2023-4522MEDIUM5.3An issue has been discovered in GitLab affecting all versions before 16.2.0. Committing directories containing LF charac...
CVE-2023-4609Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-4599MEDIUM5.4The Email Encoder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in ve...
CVE-2023-4597MEDIUM6.4The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slimstat' shortcode in...
CVE-2023-4596CRITICAL9.8The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after ...
CVE-2023-4526Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-4525Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-41269Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-41266MEDIUM6.5A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, Feb...
CVE-2023-41265CRITICAL9.9An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and ear...
CVE-2023-39559MEDIUM5.3AudimexEE 15.0 was discovered to contain a full path disclosure vulnerability.
CVE-2023-39558MEDIUM6.1AudimexEE v15.0 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the Show Kai...
CVE-2023-4611MEDIUM6.3A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is ...
CVE-2023-4296MEDIUM6.1​If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to i...
CVE-2023-41153MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in the SSH configuration tab in Usermin 2.001 allows remote attackers ...
CVE-2023-38975HIGH7.5* Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_ve...
CVE-2023-38971MEDIUM5.4Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via...
CVE-2023-32241MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPDeveloper Essential Addons for Elementor Pro plugin <= 5...
CVE-2023-4572HIGH8.8Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to potentially exploit ...
CVE-2023-4346HIGH7.5 KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable...
CVE-2023-3253MEDIUM4.3An improper authorization vulnerability exists where an authenticated, low privileged remote attacker could view a list...
CVE-2023-39678MEDIUM6.1A cross-site scripting (XSS) vulnerability in the device web interface (Log Query page) of BDCOM OLT P3310D-2AC 10.1.0F ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now