2023 CVE Vulnerabilities

31,404 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34477CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
CVE-2023-34476CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
CVE-2023-32783HIGH7.5The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by cre...
CVE-2023-23758CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
CVE-2023-23757CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
CVE-2023-3671MEDIUM6.1The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters...
CVE-2023-3650MEDIUM4.8The Bubble Menu WordPress plugin before 3.0.5 does not sanitize and escape some of its settings, which could allow high-...
CVE-2023-3575MEDIUM5.4The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which c...
CVE-2023-3524MEDIUM6.1The WPCode WordPress plugin before 2.0.13.1 does not escape generated URLs before outputting them in attributes, leading...
CVE-2023-3492MEDIUM6.8The WP Shopping Pages WordPress plugin through 1.14 does not have CSRF check in some places, and is missing sanitisation...
CVE-2023-3365HIGH8.1The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting ship...
CVE-2023-2843HIGH8.8The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parame...
CVE-2023-27373MEDIUM5.5An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attack...
CVE-2023-0604MEDIUM5.4The WP Food Manager WordPress plugin before 1.0.4 does not sanitise and escape some of its settings, which could allow h...
CVE-2023-4205Rejected reason: This was deemed as a false positive both by the reporter and upstream kernel.
CVE-2023-4194MEDIUM5.5A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filt...
CVE-2023-4147HIGH7.8A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID...
CVE-2023-36220HIGH7.2Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary ...
CVE-2023-3896HIGH7.8Divide By Zero in vim/vim from 9.0.1367-1 to 9.0.1367-3
CVE-2023-38392MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.9 ve...
CVE-2023-32090CRITICAL9.8Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
CVE-2023-0426HIGH7.5 ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported...
CVE-2023-0425HIGH7.5 ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported...
CVE-2023-39903MEDIUM5An issue was discovered in Fujitsu Software Infrastructure Manager (ISM) before 2.8.0.061. The ismsnap component (in thi...
CVE-2023-20818MEDIUM4.4In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local infor...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now