2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38976HIGH7.5An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLReques...
CVE-2023-38961CRITICAL9.8Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary c...
CVE-2023-38836HIGH8.8File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header t...
CVE-2023-38035CRITICAL9.8A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an ...
CVE-2023-32002CRITICAL9.8The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition fo...
CVE-2023-31447CRITICAL9.8user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers t...
CVE-2023-40735HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cavo – Connecting for a Safer World BUTTERFL...
CVE-2023-38899HIGH7.8SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_fi...
CVE-2023-3481MEDIUM6.1Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XS...
CVE-2023-4455MEDIUM6.5Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.
CVE-2023-4454MEDIUM5.7Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.
CVE-2023-4453MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8.
CVE-2023-40068MEDIUM5.4Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro vers...
CVE-2023-39939CRITICAL9.1SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2....
CVE-2023-39543MEDIUM6.1Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior ...
CVE-2023-4450CRITICAL9.8A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulner...
CVE-2023-39751CRITICAL9.8TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm.
CVE-2023-39750CRITICAL9.8D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vul...
CVE-2023-39749CRITICAL9.8D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is...
CVE-2023-39748HIGH7.5An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service ...
CVE-2023-39747CRITICAL9.8TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSe...
CVE-2023-39745HIGH7.5TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via th...
CVE-2023-4449HIGH8.8A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been classified...
CVE-2023-4448CRITICAL9.8A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown proces...
CVE-2023-4447CRITICAL9.8A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. This vulnerability affects unknow...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now