2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-36824HIGH8.8Redis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a command ...
CVE-2023-34117LOW3.3Relative path traversal in the Zoom Client SDK before version 5.15.0 may allow an unauthorized user to enable informatio...
CVE-2023-34116HIGH8.8Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to...
CVE-2023-28001CRITICAL9.8An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute un...
CVE-2023-26861CRITICAL9.8SQL injection vulnerability found in PrestaShop vivawallet v.1.7.10 and before allows a remote attacker to gain privileg...
CVE-2023-25606MEDIUM6.5An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyze...
CVE-2023-24881MEDIUM6.5Microsoft Teams Information Disclosure Vulnerability
CVE-2023-3621HIGH8.8A vulnerability was found in IBOS OA 4.5.5. It has been classified as critical. Affected is the function createDeleteCom...
CVE-2023-3619CRITICAL9.8A vulnerability was found in SourceCodester AC Repair and Services System 1.0 and classified as critical. This issue aff...
CVE-2023-3108MEDIUM4.7A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorith...
CVE-2023-3620MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.
CVE-2023-3617CRITICAL9.8A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. This aff...
CVE-2023-37659CRITICAL9.8xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE).
CVE-2023-37658MEDIUM5.4fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly c...
CVE-2023-37657MEDIUM5.4TwoNav v2.0.28-20230624 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-36293HIGH7.5SQL injection vulnerability in wmanager v.1.0.7 and before allows a remote attacker to obtain sensitive information via ...
CVE-2023-31818HIGH7.5An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel...
CVE-2023-37656CRITICAL9.8WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.
CVE-2023-36167Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-36164Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-36163MEDIUM6.1Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code...
CVE-2023-2746CRITICAL9.6The Rockwell Automation Enhanced HIM software contains an API that the application uses that is not protected sufficie...
CVE-2023-2072HIGH8.8The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of th...
CVE-2023-36690HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions.
CVE-2023-36522HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WePupil Quiz Expert plugin <= 1.5.0 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now