2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2803MEDIUM6.1The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape a parameter before ou...
CVE-2023-2802MEDIUM4.8The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape some of its settings,...
CVE-2023-2606MEDIUM4.8The WP Brutal AI WordPress plugin before 2.06 does not sanitise and escape some of its settings, which could allow high ...
CVE-2023-39908HIGH7.5The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations...
CVE-2023-39293CRITICAL9.8A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which co...
CVE-2023-39292CRITICAL9.8A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could ...
CVE-2023-29468CRITICAL9.8The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_...
CVE-2023-28483HIGH8.8An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write...
CVE-2023-28482MEDIUM6.5An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are a...
CVE-2023-28481HIGH8.8An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any...
CVE-2023-28480MEDIUM6.5An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined ...
CVE-2023-40360MEDIUM5.5QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whe...
CVE-2023-40312MEDIUM5.2Multiple reflected XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versi...
CVE-2023-40311MEDIUM4.8Multiple stored XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versions...
CVE-2023-38741HIGH7.5 IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement ...
CVE-2023-38721HIGH7.8The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. ...
CVE-2023-32748CRITICAL9.8The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated a...
CVE-2023-0872HIGH8The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple pl...
CVE-2023-40359CRITICAL9.8xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither...
CVE-2023-40354MEDIUM6.5An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create ser...
CVE-2023-33013HIGH8.8A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)...
CVE-2023-28768MEDIUM6.5Improper frame handling in the Zyxel XGS2220-30 firmware version V4.80(ABXN.1), XMG1930-30 firmware version V4.80(ACAR.1...
CVE-2023-4322CRITICAL9.8Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
CVE-2023-31041HIGH7.5An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information c...
CVE-2023-30754MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt plugin...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now