2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-37212HIGH8.8Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2023-37211HIGH8.8Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidenc...
CVE-2023-37210MEDIUM6.5A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confus...
CVE-2023-37209HIGH8.8A use-after-free condition existed in `NotifyOnHistoryReload` where a `LoadingSessionHistoryEntry` object was freed and ...
CVE-2023-37206MEDIUM6.5Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a ...
CVE-2023-37205MEDIUM6.5The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerability affects Firefo...
CVE-2023-37204MEDIUM6.5A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive...
CVE-2023-37203HIGH7.8Insufficient validation in the Drag and Drop API in conjunction with social engineering, may have allowed an attacker to...
CVE-2023-2880HIGH7.5Frauscher Sensortechnik GmbH FDS001 for FAdC/FAdCi v1.3.3 and all previous versions are vulnerable to a path traversal v...
CVE-2023-37208HIGH7.8When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerabilit...
CVE-2023-37207MEDIUM6.5A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, s...
CVE-2023-37202HIGH8.8Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in t...
CVE-2023-37201HIGH8.8An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerabi...
CVE-2023-34150MEDIUM5.3** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage.
CVE-2023-35786MEDIUM4.9Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
CVE-2023-33201MEDIUM5.3Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applic...
CVE-2023-31999HIGH8.8All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all req...
CVE-2023-3506MEDIUM6.1A vulnerability was found in Active It Zone Active eCommerce CMS 6.5.0. It has been declared as problematic. This vulner...
CVE-2023-3505MEDIUM6.1A vulnerability was found in Onest CRM 1.0. It has been classified as problematic. This affects an unknown part of the f...
CVE-2023-3504CRITICAL9.8A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some ...
CVE-2023-3503HIGH8.8A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulne...
CVE-2023-3502HIGH7.5A vulnerability, which was classified as critical, was found in SourceCodester Shopping Website 1.0. Affected is an unkn...
CVE-2023-2974HIGH8.1A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.ht...
CVE-2023-3460CRITICAL9.8The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary c...
CVE-2023-3139MEDIUM6.1The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now