2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1208HIGH7.2This HTTP Headers WordPress plugin before 1.18.11 allows arbitrary data to be written to arbitrary files, leading to a R...
CVE-2023-1183MEDIUM5.5A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCR...
CVE-2023-1119MEDIUM6.1The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library th...
CVE-2023-0359HIGH7.5A missing nullptr-check in handle_ra_input can cause a nullptr-deref.
CVE-2023-37288HIGH7.5SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remot...
CVE-2023-37287CRITICAL9.1SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit ...
CVE-2023-37286CRITICAL9.8SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use t...
CVE-2023-3553HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10...
CVE-2023-3552MEDIUM5.4Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
CVE-2023-3551HIGH7.2 Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
CVE-2023-32000MEDIUM4.8A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor ...
CVE-2023-37270HIGH8.8Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the log...
CVE-2023-37269MEDIUM4.8Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Users with the `backen...
CVE-2023-37262HIGH8.8CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to versions 1...
CVE-2023-37261HIGH8.8OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. This issue affects every versi...
CVE-2023-37173CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command para...
CVE-2023-37172CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter...
CVE-2023-37171CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser para...
CVE-2023-37170CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnera...
CVE-2023-20180MEDIUM4.3A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct ...
CVE-2023-20133MEDIUM5.4A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a ...
CVE-2023-36994CRITICAL9.8In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the ser...
CVE-2023-36993CRITICAL9.8The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset func...
CVE-2023-36992HIGH7.2PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP ...
CVE-2023-36256MEDIUM6.5The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacke...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now