2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1862HIGH7.3Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe b...
CVE-2023-35882MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor Super Socializer plugin <= 7.13.52 ...
CVE-2023-35878MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Vadym K. Extra User Details plugin <= 0.5 versions.
CVE-2023-26436HIGH8.8Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not proper...
CVE-2023-26435MEDIUM5It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT doc...
CVE-2023-26434MEDIUM4.3When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. At...
CVE-2023-26433MEDIUM4.3When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. At...
CVE-2023-26432MEDIUM4.3When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. At...
CVE-2023-26431MEDIUM4.3IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers wit...
CVE-2023-26429MEDIUM5.3Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected c...
CVE-2023-26428MEDIUM6.5Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same con...
CVE-2023-26427LOW3.3Default permissions for a properties file were too permissive. Local system users could read potentially sensitive infor...
CVE-2023-35884MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions.
CVE-2023-3325CRITICAL9.8The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique ...
CVE-2023-3320HIGH8.8The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,...
CVE-2023-3315MEDIUM4.3Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission ...
CVE-2023-32659MEDIUM6.1 SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an at...
CVE-2023-29158CRITICAL9.1 SUBNET PowerSYSTEM Center versions 2020 U10 and prior are vulnerable to replay attacks which may result in a denial-o...
CVE-2023-3312HIGH7.5A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, duri...
CVE-2023-3022MEDIUM5.5A flaw was found in the IPv6 module of the Linux kernel. The arg.result was not used consistently in fib6_rule_lookup, s...
CVE-2023-35843HIGH7.5NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access...
CVE-2023-34461MEDIUM5.4PyBB is an open source bulletin board. A manual code review of the PyBB bulletin board server has revealed that a vulner...
CVE-2023-34167MEDIUM5.3Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-par...
CVE-2023-34166HIGH7.5Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerabi...
CVE-2023-34163HIGH7.5Permission control vulnerability in the window management module.Successful exploitation of this vulnerability may cause...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now