2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-40711HIGH7.5Veilid before 0.1.9 does not check the size of uncompressed data during decompression upon an envelope receipt, which al...
CVE-2023-2971MEDIUM6.5Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files an...
CVE-2023-2318CRITICAL9.6DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows...
CVE-2023-2317CRITICAL9.6DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run a...
CVE-2023-2316HIGH7.4Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and ex...
CVE-2023-2110HIGH7.1Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access l...
CVE-2023-4433MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
CVE-2023-4432MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
CVE-2023-40175CRITICAL9.8Puma is a Ruby/Rack web server built for parallelism. Prior to versions 6.3.1 and 5.6.7, puma exhibited incorrect behavi...
CVE-2023-40174CRITICAL9.8Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html...
CVE-2023-40173HIGH7.5Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html...
CVE-2023-40172HIGH8.8Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html...
CVE-2023-40037MEDIUM6.5Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with co...
CVE-2023-38839HIGH7.5SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via theID...
CVE-2023-20212HIGH7.5A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of serv...
CVE-2023-4422MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
CVE-2023-38911MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted pay...
CVE-2023-38910MEDIUM6.1CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HT...
CVE-2023-38890HIGH8.8Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form,...
CVE-2023-27471MEDIUM5.5An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. UEFI implementations do not correctly protect a...
CVE-2023-4415HIGH8.8A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is s...
CVE-2023-4414CRITICAL9.8A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230807. It has been declared as critical. Aff...
CVE-2023-32130MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.6 versions.
CVE-2023-32122MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spiffy Plugins Spiffy Calendar plugin <= 4.9.3 versions.
CVE-2023-4413Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn b...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now