2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38037MEDIUM5.5ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissi...
CVE-2023-28362MEDIUM4The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value...
CVE-2023-28120MEDIUM5.3There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user inp...
CVE-2023-27539MEDIUM5.3There is a denial of service vulnerability in the header parsing component of Rack.
CVE-2023-27531MEDIUM5.3There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code
CVE-2023-23913MEDIUM6.3There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML ...
CVE-2023-35685HIGH7.8In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This...
CVE-2023-52955HIGH7.5Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulner...
CVE-2023-52954HIGH7.5Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability...
CVE-2023-52953CRITICAL9.1Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affec...
CVE-2023-6605HIGH7.2A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on ...
CVE-2023-6604MEDIUM5.3A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentiall...
CVE-2023-6601MEDIUM4.7A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggerin...
CVE-2023-23672MEDIUM5.4Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP.This issue affects GiveWP: from n/a through 2.25.1.
CVE-2023-48758HIGH7.1Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access C...
CVE-2023-48739MEDIUM5.3Missing Authorization vulnerability in Porto Theme Porto Theme - Functionality porto-functionality allows Exploiting Inc...
CVE-2023-47807MEDIUM4.3Missing Authorization vulnerability in 10Web 10WebAnalytics wd-google-analytics allows Exploiting Incorrectly Configured...
CVE-2023-47778MEDIUM4.3Missing Authorization vulnerability in LuckyWP LuckyWP Scripts Control luckywp-scripts-control allows Exploiting Incorre...
CVE-2023-45633MEDIUM6.5Missing Authorization vulnerability in IDX IMPress Listings allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2023-45272MEDIUM4.3Missing Authorization vulnerability in 10Web 10Web Map Builder for Google Maps allows Exploiting Incorrectly Configured ...
CVE-2023-40327MEDIUM6.5Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Con...
CVE-2023-39994MEDIUM4.3Missing Authorization vulnerability in Repute InfoSystems ARMember Premium allows Exploiting Incorrectly Configured Acce...
CVE-2023-32240MEDIUM5.4Missing Authorization vulnerability in Xtemos WoodMart allows Exploiting Incorrectly Configured Access Control Security ...
CVE-2023-47693HIGH7.5Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 al...
CVE-2023-47692MEDIUM4.3Missing Authorization vulnerability in flothemesplugins Flo Forms flo-forms allows Exploiting Incorrectly Configured Acc...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now