2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-3396MEDIUM6.5A vulnerability was found in Campcodes Retro Cellphone Online Store 1.0. It has been declared as critical. Affected by t...
CVE-2023-36632HIGH7.5The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum ...
CVE-2023-36630HIGH8.8In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.
CVE-2023-36612HIGH7.5Directory traversal can occur in the Basecamp com.basecamp.bc3 application before 4.2.1 for Android, which may allow an ...
CVE-2023-3388MEDIUM6.1The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_...
CVE-2023-3387MEDIUM5.4The Lana Text to Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lana_text_to_image' an...
CVE-2023-3197CRITICAL9.8The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versi...
CVE-2023-1722HIGH8.8Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible b...
CVE-2023-1724MEDIUM5.4Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the...
CVE-2023-1721HIGH7.2Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible b...
CVE-2023-35932HIGH8.8jcvi is a Python library to facilitate genome assembly, annotation, and comparative genomics. A configuration injection ...
CVE-2023-1783HIGH7.6OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible bec...
CVE-2023-35928HIGH8.8Nextcloud Server is a space for data storage on Nextcloud, a self-hosted productivity playform. In NextCloud Server vers...
CVE-2023-35927HIGH8.1NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform...
CVE-2023-35173MEDIUM6.5Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client sid...
CVE-2023-35172CRITICAL9.1NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform...
CVE-2023-35171MEDIUM6.1NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform...
CVE-2023-35169CRITICAL9.8PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Pr...
CVE-2023-35165HIGH8.8AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in c...
CVE-2023-35163MEDIUM5.2Vega is a decentralized trading platform that allows pseudo-anonymous trading of derivatives on a blockchain. Prior to v...
CVE-2023-35154MEDIUM6.5Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1....
CVE-2023-34254HIGH7.2The GLPI Agent is a generic management agent. Prior to version 1.5, if glpi-agent is running remoteinventory task agains...
CVE-2023-3212MEDIUM4.4A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file s...
CVE-2023-36348HIGH8.8POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename p...
CVE-2023-36346MEDIUM6.1POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now