2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27439MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gl_SPICE New Adman plugin <= 1.6.8 versions.
CVE-2023-3351Rejected reason: Wrong year requested.
CVE-2023-34981HIGH7.5A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response di...
CVE-2023-34340CRITICAL9.8Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo:...
CVE-2023-3339HIGH7.5A vulnerability has been found in code-projects Agro-School Management System 1.0 and classified as critical. Affected b...
CVE-2023-34563CRITICAL9.8netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.
CVE-2023-3220MEDIUM5.5An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_...
CVE-2023-35885CRITICAL9.8CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
CVE-2023-35166HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t...
CVE-2023-33869CRITICAL9.8 Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root ...
CVE-2023-32274HIGH7.5 Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android applica...
CVE-2023-2400LOW2.7Improper deletion of resource in the user management feature in Devolutions Server 2023.1.8 and earlier allows an admin...
CVE-2023-3340CRITICAL9.8A vulnerability was found in SourceCodester Online School Fees System 1.0 and classified as critical. Affected by this i...
CVE-2023-34600CRITICAL9.8Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
CVE-2023-34541CRITICAL9.8Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.
CVE-2023-2533HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific condition...
CVE-2023-35095MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Flothemes Flo Forms – Easy Drag & Drop Form Builder pl...
CVE-2023-34597MEDIUM6.5A vulnerability in Fibaro Motion Sensor firmware v3.4 allows attackers to cause a Denial of Service (DoS) via a crafted ...
CVE-2023-34596MEDIUM6.5A vulnerability in Aeotec WallMote Switch firmware v2.3 allows attackers to cause a Denial of Service (DoS) via a crafte...
CVE-2023-33495MEDIUM6.1Craft CMS through 4.4.9 is vulnerable to HTML Injection.
CVE-2023-3337CRITICAL9.8A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affec...
CVE-2023-35854CRITICAL9.8Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain...
CVE-2023-1999HIGH7.5There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop ...
CVE-2023-35098MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 v...
CVE-2023-35097MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Internet Marketing Dojo WP Affiliate Links plugin <= 0.1.1...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now