2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36824 | HIGH | 8.8 | 74.8% | Jul 11, 2023 | Redis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a command ... |
| CVE-2023-34117 | LOW | 3.3 | 0.2% | Jul 11, 2023 | Relative path traversal in the Zoom Client SDK before version 5.15.0 may allow an unauthorized user to enable informatio... |
| CVE-2023-34116 | HIGH | 8.8 | 0.9% | Jul 11, 2023 | Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to... |
| CVE-2023-28001 | CRITICAL | 9.8 | 0.4% | Jul 11, 2023 | An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute un... |
| CVE-2023-26861 | CRITICAL | 9.8 | 0.8% | Jul 11, 2023 | SQL injection vulnerability found in PrestaShop vivawallet v.1.7.10 and before allows a remote attacker to gain privileg... |
| CVE-2023-25606 | MEDIUM | 6.5 | 0.5% | Jul 11, 2023 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyze... |
| CVE-2023-24881 | MEDIUM | 6.5 | 1.5% | Jul 11, 2023 | Microsoft Teams Information Disclosure Vulnerability |
| CVE-2023-3621 | HIGH | 8.8 | 0.6% | Jul 11, 2023 | A vulnerability was found in IBOS OA 4.5.5. It has been classified as critical. Affected is the function createDeleteCom... |
| CVE-2023-3619 | CRITICAL | 9.8 | 0.4% | Jul 11, 2023 | A vulnerability was found in SourceCodester AC Repair and Services System 1.0 and classified as critical. This issue aff... |
| CVE-2023-3108 | MEDIUM | 4.7 | 0.2% | Jul 11, 2023 | A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorith... |
| CVE-2023-3620 | MEDIUM | 5.4 | 0.5% | Jul 11, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1. |
| CVE-2023-3617 | CRITICAL | 9.8 | 0.8% | Jul 11, 2023 | A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. This aff... |
| CVE-2023-37659 | CRITICAL | 9.8 | 1.4% | Jul 11, 2023 | xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE). |
| CVE-2023-37658 | MEDIUM | 5.4 | 0.3% | Jul 11, 2023 | fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly c... |
| CVE-2023-37657 | MEDIUM | 5.4 | 0.3% | Jul 11, 2023 | TwoNav v2.0.28-20230624 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2023-36293 | HIGH | 7.5 | 0.6% | Jul 11, 2023 | SQL injection vulnerability in wmanager v.1.0.7 and before allows a remote attacker to obtain sensitive information via ... |
| CVE-2023-31818 | HIGH | 7.5 | 0.8% | Jul 11, 2023 | An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel... |
| CVE-2023-37656 | CRITICAL | 9.8 | 1.3% | Jul 11, 2023 | WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload. |
| CVE-2023-36167 | — | — | — | Jul 11, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-36164 | — | — | — | Jul 11, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2023-36163 | MEDIUM | 6.1 | 2.9% | Jul 11, 2023 | Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code... |
| CVE-2023-2746 | CRITICAL | 9.6 | 0.4% | Jul 11, 2023 | The Rockwell Automation Enhanced HIM software contains an API that the application uses that is not protected sufficie... |
| CVE-2023-2072 | HIGH | 8.8 | 0.8% | Jul 11, 2023 | The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of th... |
| CVE-2023-36690 | HIGH | 8.8 | 0.2% | Jul 11, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions. |
| CVE-2023-36522 | HIGH | 8.8 | 0.2% | Jul 11, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WePupil Quiz Expert plugin <= 1.5.0 versions. |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now