2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-24420MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact F...
CVE-2023-3276HIGH7.5A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this is...
CVE-2023-3275CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnera...
CVE-2023-3274HIGH8.8A vulnerability classified as critical has been found in code-projects Supplier Management System 1.0. Affected is an un...
CVE-2023-25972MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in IKSWEB WordPress Старт plugin <= 3.7 versions.
CVE-2023-25450HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin <= 2....
CVE-2023-23802HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions...
CVE-2023-25449HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions.
CVE-2023-32229MEDIUM6.5Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the ...
CVE-2023-28175HIGH7.7Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access ...
CVE-2023-2847HIGH7.8 During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with th...
CVE-2023-35030HIGH8.8Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 thro...
CVE-2023-2270HIGH7.8The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start variou...
CVE-2023-3193MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4...
CVE-2023-35029MEDIUM6.1Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Li...
CVE-2023-25683HIGH7.5IBM PowerVM Hypervisor FW950.00 through FW950.71, FW1010.00 through FW1010.40, FW1020.00 through FW1020.20, and FW1030.0...
CVE-2023-34452MEDIUM6.1Grav is a flat-file content management system. In versions 1.7.42 and prior, the "/forgot_password" page has a self-refl...
CVE-2023-34448HIGH7.2Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side templ...
CVE-2023-34253HIGH7.2Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prev...
CVE-2023-34252HIGH7.2Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filt...
CVE-2023-34251HIGH7.2Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection...
CVE-2023-2820MEDIUM6.8An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (...
CVE-2023-2819MEDIUM4.3A stored cross-site scripting vulnerability in the Sources UI in Proofpoint Threat Response/ Threat Response Auto Pull (...
CVE-2023-34565MEDIUM5.4Netbox 3.5.1 is vulnerable to Cross Site Scripting (XSS) in the "Create Wireless LAN Groups" function.
CVE-2023-34449MEDIUM5.3ink! is an embedded domain specific language to write smart contracts in Rust for blockchains built on the Substrate fra...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now