2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-26115HIGH7.5All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of...
CVE-2023-33842MEDIUM5.5IBM SPSS Modeler on Windows 17.0, 18.0, 18.2.2, 18.3, 18.4, and 18.5 requires the end user to have access to the server ...
CVE-2023-28956HIGH7.8IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges ...
CVE-2023-33405MEDIUM6.1Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.
CVE-2023-24261HIGH7.2A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code ...
CVE-2023-3110HIGH8.8Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave ...
CVE-2023-33591MEDIUM6.1User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnera...
CVE-2023-33289HIGH7.5The urlnorm crate through 0.1.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to lib.rs...
CVE-2023-25435MEDIUM5.5libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesShifted8bits() at /libtiff/tools/tiffcrop.c:3753.
CVE-2023-0972HIGH8.8Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave...
CVE-2023-0971HIGH8.8A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration...
CVE-2023-0970MEDIUM6.8Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with i...
CVE-2023-0969LOW3.5A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manip...
CVE-2023-2911HIGH7.5If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `st...
CVE-2023-2829HIGH7.5A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validat...
CVE-2023-2828HIGH7.5Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the...
CVE-2023-0026HIGH7.5An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos O...
CVE-2023-33725MEDIUM6.1Broadleaf 5.x and 6.x (including 5.2.25-GA and 6.2.6-GA) was discovered to contain a cross-site scripting (XSS) vulnerab...
CVE-2023-27243HIGH7.5An access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a...
CVE-2023-27432MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WpSimpleTools Manage Upload Limit plugin <= 1.0.4 versions...
CVE-2023-27429MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Automattic - Jetpack CRM team Jetpack CRM plugin <= 5....
CVE-2023-27414MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Popup Box Team Popup box plugin <= 3.4.4 versions.
CVE-2023-33584CRITICAL9.8Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to ...
CVE-2023-27450MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.29.2 versio...
CVE-2023-27443MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Grant Kimball Simple Vimeo Shortcode plugin <= 2...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now