2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28598MEDIUM6.5Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malic...
CVE-2023-28303LOW3.3Windows Snipping Tool Information Disclosure Vulnerability
CVE-2023-27837CRITICAL9.8TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key par...
CVE-2023-20867LOW3.9A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the con...
CVE-2023-33695HIGH7.1Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile()...
CVE-2023-33621MEDIUM5.9GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server ...
CVE-2023-27624MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcelotorres Redirect After Login plugin <= 0.1.9 ver...
CVE-2023-25978MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nate Reist Protected Posts Logout Button plugin <= 1.4...
CVE-2023-35064CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile...
CVE-2023-33568HIGH7.5An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's...
CVE-2023-28620MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cyberus Labs Cyberus Key plugin <= 1.0 versions.
CVE-2023-26538MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kamyabsoft Chat Bee plugin <= 1.1.0 versions.
CVE-2023-26528MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in jinit9906 Shipyaari Shipping Management plugin <= 1.0 ...
CVE-2023-25964MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Noah Hearle, Design Extreme We’re Open! plugin <= 1.46...
CVE-2023-23831MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Rating-Widget Rating-Widget: Star Review System ...
CVE-2023-3050CRITICAL9.8Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allow...
CVE-2023-3049CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection. This issue affe...
CVE-2023-3048CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authenticati...
CVE-2023-3047CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allow...
CVE-2023-2807CRITICAL9.8Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated a...
CVE-2023-3218MEDIUM4.4Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.
CVE-2023-32548HIGH8.1OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-...
CVE-2023-32546MEDIUM4.4Code injection vulnerability exists in Chatwork Desktop Application (Mac) 2.6.43 and earlier. If this vulnerability is e...
CVE-2023-31198HIGH7.2OS command injection vulnerability exists in Wi-Fi AP UNIT allows. If this vulnerability is exploited, a remote authenti...
CVE-2023-31196HIGH7.5Missing authentication for critical function in Wi-Fi AP UNIT allows a remote unauthenticated attacker to obtain sensiti...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now