2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3473CRITICAL9.8A vulnerability, which was classified as critical, was found in Campcodes Retro Cellphone Online Store 1.0. Affected is ...
CVE-2023-28387MEDIUM5.5"NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard...
CVE-2023-32622HIGH7.2Improper neutralization of special elements in WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an...
CVE-2023-32621HIGH7.2WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to upload arbitrary f...
CVE-2023-32620MEDIUM6.5Improper authentication vulnerability in WL-WN531AX2 firmware versions prior to 2023526 allows a network-adjacent attack...
CVE-2023-32613HIGH8.1Exposure of resource to wrong sphere issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow a n...
CVE-2023-32612HIGH7.2Client-side enforcement of server-side security issue exists in WL-WN531AX2 firmware versions prior to 2023526, which ma...
CVE-2023-2846CRITICAL9.1Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series main modules...
CVE-2023-26135CRITICAL9.8All versions of the package flatnest are vulnerable to Prototype Pollution via the nest() function in the flatnest/nest....
CVE-2023-36539HIGH7.5Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
CVE-2023-32608MEDIUM6.5Directory traversal vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions...
CVE-2023-32607MEDIUM5.4Stored cross-site scripting vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier...
CVE-2023-3249CRITICAL9.8The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in version...
CVE-2023-3063HIGH8.8The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up...
CVE-2023-36347HIGH7.5A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to down...
CVE-2023-33336MEDIUM4.8Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbit...
CVE-2023-2834CRITICAL9.8The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is ...
CVE-2023-3469MEDIUM4.8Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.2.
CVE-2023-36146MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was found in Multilaser RE 170 using firmware 2.2.6733.
CVE-2023-36143HIGH8.8Maxprint Maxlink 1200G v3.4.11E has an OS command injection vulnerability in the "Diagnostic tool" functionality of the ...
CVE-2023-3465MEDIUM6.1A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected b...
CVE-2023-3464MEDIUM6.1A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected...
CVE-2023-36607MEDIUM5.3The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could...
CVE-2023-36470HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creat...
CVE-2023-36469HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who ca...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now