2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40035HIGH7.2Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can le...
CVE-2023-40176MEDIUM5.4XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered ...
CVE-2023-40025HIGH7.1Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version ...
CVE-2023-40612HIGH8In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FI...
CVE-2023-20234MEDIUM6A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overw...
CVE-2023-20230MEDIUM5.4A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (...
CVE-2023-20200MEDIUM6.3A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Serie...
CVE-2023-20169HIGH7.4A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco...
CVE-2023-20168MEDIUM6.5A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, loc...
CVE-2023-20115MEDIUM5.4A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in stand...
CVE-2023-40270Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-38831. Reason: This candidate is a reservation d...
CVE-2023-39583Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-38831. Reason: This candidate is a reservation d...
CVE-2023-38831HIGH7.8RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a...
CVE-2023-40273HIGH8The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the...
CVE-2023-39441MEDIUM5.9Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 ar...
CVE-2023-37379HIGH8.1Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated ...
CVE-2023-1409HIGH7.5If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options ...
CVE-2023-41126Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-41125Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-41124Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-41123Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-41122Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-32509MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 ...
CVE-2023-32505MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Arshid Easy Hide Login plugin <= 1.0.7 versions.
CVE-2023-32300MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now