2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1208 | HIGH | 7.2 | 1.3% | Jul 10, 2023 | This HTTP Headers WordPress plugin before 1.18.11 allows arbitrary data to be written to arbitrary files, leading to a R... |
| CVE-2023-1183 | MEDIUM | 5.5 | 65.7% | Jul 10, 2023 | A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCR... |
| CVE-2023-1119 | MEDIUM | 6.1 | 1.1% | Jul 10, 2023 | The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library th... |
| CVE-2023-0359 | HIGH | 7.5 | 0.7% | Jul 10, 2023 | A missing nullptr-check in handle_ra_input can cause a nullptr-deref. |
| CVE-2023-37288 | HIGH | 7.5 | 0.7% | Jul 10, 2023 | SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remot... |
| CVE-2023-37287 | CRITICAL | 9.1 | 0.7% | Jul 10, 2023 | SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit ... |
| CVE-2023-37286 | CRITICAL | 9.8 | 0.8% | Jul 10, 2023 | SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use t... |
| CVE-2023-3553 | HIGH | 7.5 | 0.7% | Jul 8, 2023 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10... |
| CVE-2023-3552 | MEDIUM | 5.4 | 0.5% | Jul 8, 2023 | Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10. |
| CVE-2023-3551 | HIGH | 7.2 | 0.9% | Jul 8, 2023 | Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. |
| CVE-2023-32000 | MEDIUM | 4.8 | 0.3% | Jul 8, 2023 | A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor ... |
| CVE-2023-37270 | HIGH | 8.8 | 3.9% | Jul 7, 2023 | Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the log... |
| CVE-2023-37269 | MEDIUM | 4.8 | 1.6% | Jul 7, 2023 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Users with the `backen... |
| CVE-2023-37262 | HIGH | 8.8 | 0.7% | Jul 7, 2023 | CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to versions 1... |
| CVE-2023-37261 | HIGH | 8.8 | 0.6% | Jul 7, 2023 | OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. This issue affects every versi... |
| CVE-2023-37173 | CRITICAL | 9.8 | 1.7% | Jul 7, 2023 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command para... |
| CVE-2023-37172 | CRITICAL | 9.8 | 1.7% | Jul 7, 2023 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter... |
| CVE-2023-37171 | CRITICAL | 9.8 | 1.7% | Jul 7, 2023 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser para... |
| CVE-2023-37170 | CRITICAL | 9.8 | 1.4% | Jul 7, 2023 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnera... |
| CVE-2023-20180 | MEDIUM | 4.3 | 0.3% | Jul 7, 2023 | A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct ... |
| CVE-2023-20133 | MEDIUM | 5.4 | 0.5% | Jul 7, 2023 | A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a ... |
| CVE-2023-36994 | CRITICAL | 9.8 | 0.7% | Jul 7, 2023 | In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the ser... |
| CVE-2023-36993 | CRITICAL | 9.8 | 0.8% | Jul 7, 2023 | The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset func... |
| CVE-2023-36992 | HIGH | 7.2 | 1.0% | Jul 7, 2023 | PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP ... |
| CVE-2023-36256 | MEDIUM | 6.5 | 0.3% | Jul 7, 2023 | The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacke... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now