2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-30920MEDIUM5.5In messaging service, there is a missing permission check. This could lead to local information disclosure with no addit...
CVE-2023-30919MEDIUM5.5In messaging service, there is a missing permission check. This could lead to local information disclosure with no addit...
CVE-2023-30918MEDIUM5.5In telephony service, there is a missing permission check. This could lead to local information disclosure with no addit...
CVE-2023-30917HIGH7.8In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no add...
CVE-2023-30916HIGH7.8In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no add...
CVE-2023-30913MEDIUM5.5In telephony service, there is a missing permission check. This could lead to local information disclosure with no addit...
CVE-2023-29414HIGH7.8 A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause u...
CVE-2023-37200MEDIUM5.5 A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confiden...
CVE-2023-37199HIGH7.2 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code e...
CVE-2023-32200HIGH8.8There is insufficient restrictions of called script functions in Apache Jena versions 4.8.0 and earlier. It allows a r...
CVE-2023-2763HIGH7.8Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading...
CVE-2023-2762HIGH7.8A Use-After-Free vulnerability in SLDPRT file reading procedure exists in SOLIDWORKS Desktop from Release SOLIDWORKS 202...
CVE-2023-37198HIGH7.2 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote co...
CVE-2023-37197HIGH8.8 A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerab...
CVE-2023-37196HIGH8.8 A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerabil...
CVE-2023-3525HIGH7.5The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validati...
CVE-2023-3369MEDIUM4.8The About Me 3000 widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version...
CVE-2023-3202MEDIUM4.3The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the m...
CVE-2023-3199MEDIUM4.3The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the m...
CVE-2023-3168MEDIUM6.1The WP Reroute Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions ...
CVE-2023-3167MEDIUM6.1The Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to,...
CVE-2023-3166MEDIUM6.1The Lana Email Logger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions...
CVE-2023-3158MEDIUM6.1The Mail Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up t...
CVE-2023-3135MEDIUM6.1The Mailtree Log Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions...
CVE-2023-3122MEDIUM6.1The GD Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now