2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38688HIGH7.5twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication...
CVE-2023-38964MEDIUM6.1Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2023-38686MEDIUM5.3Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send email...
CVE-2023-38497HIGH7.3Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Ru...
CVE-2023-38494HIGH7.5MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud ver...
CVE-2023-38487HIGH8.2HedgeDoc is software for creating real-time collaborative markdown notes. Prior to version 1.9.9, the API of HedgeDoc 1 ...
CVE-2023-37896HIGH7.5Nuclei is a vulnerability scanner. Prior to version 2.9.9, a security issue in the Nuclei project affected users utilizi...
CVE-2023-37470CRITICAL9.8Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3,...
CVE-2023-36480CRITICAL9.8The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike serv...
CVE-2023-29689CRITICAL9.8PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in...
CVE-2023-29505HIGH8.8An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross...
CVE-2023-4135MEDIUM6.5A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate a...
CVE-2023-34038MEDIUM5.3VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be abl...
CVE-2023-34037MEDIUM5.3VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able...
CVE-2023-39379HIGH7.5Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) i...
CVE-2023-4142HIGH8.8The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin...
CVE-2023-4141HIGH8.8The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin...
CVE-2023-4140HIGH8.8The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including...
CVE-2023-4139HIGH7.5The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing...
CVE-2023-4002MEDIUM6.5An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting...
CVE-2023-39343MEDIUM4.3Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form...
CVE-2023-38708HIGH8.8Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path ...
CVE-2023-30146HIGH7.5Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy o...
CVE-2023-3373CRITICAL9.1Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model ...
CVE-2023-38991MEDIUM5.4An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now