2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-36462MEDIUM5.4Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 2.6.0 and prior to versi...
CVE-2023-35934HIGH8.2yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external down...
CVE-2023-30195HIGH7.5In the module "Detailed Order" (lgdetailedorder) in version up to 1.1.20 from Linea Grafica for PrestaShop, a guest can ...
CVE-2023-3529HIGH7.5A vulnerability classified as problematic has been found in Rotem Dynamics Rotem CRM up to 20230729. This affects an unk...
CVE-2023-36461HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Masto...
CVE-2023-36460CRITICAL9.9Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versi...
CVE-2023-36459MEDIUM6.1Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 1.3 and prior to version...
CVE-2023-36456HIGH7.3authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the so...
CVE-2023-3528CRITICAL9.8A vulnerability was found in ThinuTech ThinuCMS 1.5. It has been rated as critical. Affected by this issue is some unkno...
CVE-2023-1298MEDIUM6.1ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was ...
CVE-2023-37454MEDIUM5.5An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write ...
CVE-2023-37453MEDIUM4.6An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in r...
CVE-2023-37260HIGH7.5league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2...
CVE-2023-36830HIGH7.8SQLFluff is a SQL linter. Prior to version 2.1.2, in environments where untrusted users have access to the config files,...
CVE-2023-36823MEDIUM6.1Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak a...
CVE-2023-34193HIGH8.8File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obt...
CVE-2023-34192CRITICAL9Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary co...
CVE-2023-30321CRITICAL9Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine...
CVE-2023-30320CRITICAL9Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine c...
CVE-2023-30319CRITICAL9.6Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine co...
CVE-2023-29382CRITICAL9.8An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preaut...
CVE-2023-29381CRITICAL9.8An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sen...
CVE-2023-37136MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attac...
CVE-2023-37135MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execu...
CVE-2023-37134MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now