2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4030HIGH7.8A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the ...
CVE-2023-4029MEDIUM6.7A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow ...
CVE-2023-4028MEDIUM6.7A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may...
CVE-2023-3078HIGH7.8An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an a...
CVE-2023-34419MEDIUM6.7A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an att...
CVE-2023-2917CRITICAL9.8The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an imp...
CVE-2023-2915CRITICAL9.1The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to imprope...
CVE-2023-2914HIGH7.5The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer ove...
CVE-2023-31079MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Roberts Tippy plugin <= 6.2.1 versions.
CVE-2023-31072MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Praveen Goswami Advanced Category Template plugin <= 0.1 v...
CVE-2023-28783MEDIUM5.4Auth. (shop manager+) Stored Cross-Site Scripting (XSS) vulnerability in PHPRADAR Woocommerce Tip/Donation plugin <= 1.2...
CVE-2023-28693MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Balasaheb Bhise Advanced Youtube Channel Pagination plugin...
CVE-2023-40272HIGH7.5Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in ...
CVE-2023-34412MEDIUM4.8A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 ...
CVE-2023-4394MEDIUM6A use-after-free flaw was found in btrfs_get_dev_args_from_path in fs/btrfs/volumes.c in btrfs file-system in the Linux ...
CVE-2023-38902HIGH8.8A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 ser...
CVE-2023-38838HIGH7.5SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via the e...
CVE-2023-31091MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= ...
CVE-2023-31074MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in hupe13 Extensions for Leaflet Map plugin <= 3.4.1 versions...
CVE-2023-26530MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paul Kehrer Updraft plugin <= 0.6.1 versions.
CVE-2023-3698HIGH8.1Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the inte...
CVE-2023-3697HIGH8.8Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the inte...
CVE-2023-2910HIGH8.8Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service fun...
CVE-2023-29182MEDIUM6.7A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to e...
CVE-2023-31076MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now