2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38909MEDIUM6.5An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, a...
CVE-2023-38908MEDIUM6.5An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, a...
CVE-2023-38906MEDIUM6.5An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200...
CVE-2023-4303MEDIUM6.1Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in ...
CVE-2023-4302MEDIUM4.3A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission t...
CVE-2023-4301MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers to conn...
CVE-2023-25915HIGH8.8Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system...
CVE-2023-25914HIGH8.8Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server throu...
CVE-2023-25913HIGH7.5Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive infor...
CVE-2023-38158LOW3.1Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2023-36787HIGH8.8Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-4459MEDIUM5.5A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking s...
CVE-2023-4417MEDIUM6.5Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier ...
CVE-2023-4373CRITICAL9.8 Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager v...
CVE-2023-40352HIGH7.2McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by l...
CVE-2023-4456MEDIUM6.5A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This is...
CVE-2023-3954MEDIUM6.1The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before...
CVE-2023-3936MEDIUM6.1The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2023-3667MEDIUM4.8The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high p...
CVE-2023-3604HIGH7.5The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a craf...
CVE-2023-3366MEDIUM4.3The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipme...
CVE-2023-39660CRITICAL9.8An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a craft...
CVE-2023-39106HIGH8.8An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via t...
CVE-2023-39094MEDIUM5.4Cross Site Scripting vulnerability in ZeroWdd studentmanager v.1.0 allows a remote attacker to execute arbitrary code vi...
CVE-2023-39061LOW3.5Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privilege...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now