2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34162HIGH7.5Version update determination vulnerability in the user profile module.Successful exploitation of this vulnerability may ...
CVE-2023-34161HIGH7.5nappropriate authorization vulnerability in the SettingsProvider module.Successful exploitation of this vulnerability ma...
CVE-2023-34160MEDIUM5.3Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-par...
CVE-2023-34159CRITICAL9.8Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to pr...
CVE-2023-34158MEDIUM5.3Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-par...
CVE-2023-34156MEDIUM5.3Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful exploitation of this vulnera...
CVE-2023-34155HIGH7.5Vulnerability of unauthorized calling on HUAWEI phones and tablets.Successful exploitation of this vulnerability may aff...
CVE-2023-31411CRITICAL9.8A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of AP...
CVE-2023-31410HIGH7.4A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transpo...
CVE-2023-35779MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Seed Webs Seed Fonts plugin <= 2.3.1 versions.
CVE-2023-35776MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0...
CVE-2023-35775MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Backup Solutions WP Backup Manager plugin <= 1.13.1 ver...
CVE-2023-35772MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Alain Gonzalez Google Map Shortcode plugin <= 3.1.2 versio...
CVE-2023-3318MEDIUM5.4A vulnerability was found in SourceCodester Resort Management System 1.0. It has been declared as problematic. Affected ...
CVE-2023-34373HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Project Manager plugin <= 3.3.93 versions.
CVE-2023-33213MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Display Custom Fields – wpView plugin <= 1.3....
CVE-2023-2907CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQ...
CVE-2023-3316MEDIUM6.5A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path tha...
CVE-2023-27992CRITICAL9.8The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, ...
CVE-2023-34417CRITICAL9.8Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2023-34416CRITICAL9.8Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidenc...
CVE-2023-34415MEDIUM6.1When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox ...
CVE-2023-34414LOW3.1The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts ...
CVE-2023-2899MEDIUM5.4The Google Map Shortcode WordPress plugin through 3.1.2 does not validate and escape some of its shortcode attributes be...
CVE-2023-2812MEDIUM4.8The Ultimate Dashboard WordPress plugin before 3.7.6 does not sanitise and escape some of its settings, which could allo...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now