2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-35042CRITICAL9.8GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime(...
CVE-2023-34581CRITICAL9.8Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/...
CVE-2023-32961MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.3 versions.
CVE-2023-32118MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPoperation SALERT – Fake Sales Notification WooCommerce p...
CVE-2023-31236MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in unFocus Projects Scripts n Styles plugin <= 3.5.7 vers...
CVE-2023-34494HIGH7.5NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c.
CVE-2023-34488HIGH7.8NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes...
CVE-2023-30753MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Phan Chuong IP Metaboxes plugin <= 2.1.1.
CVE-2023-30745MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Phan Chuong IP Metaboxes plugin <= 2.1.1 versions.
CVE-2023-23822MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ludwig Media UTM Tracker plugin <= 1.3.1 versions.
CVE-2023-23819MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Rolands Umbrovskis itemprop WP for SERP/SEO Rich snipp...
CVE-2023-34855MEDIUM4.8A Cross Site Scripting (XSS) vulnerability in Youxun Electronic Equipment (Shanghai) Co., Ltd AC Centralized Management ...
CVE-2023-33492MEDIUM5.4EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-33290HIGH7.5The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to ...
CVE-2023-33253HIGH8.8LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an exe...
CVE-2023-23818MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Aviplugins.Com WP Register Profile With Shortcode plug...
CVE-2023-26133CRITICAL9.8All versions of the package progressbar.js are vulnerable to Prototype Pollution via the function extend() in the file u...
CVE-2023-35036CRITICAL9.1In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023....
CVE-2023-35035HIGH8.8Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V...
CVE-2023-35034CRITICAL9.8Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and ...
CVE-2023-35033HIGH8.8Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V...
CVE-2023-35032HIGH8.8Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and ...
CVE-2023-35031HIGH8.8Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V...
CVE-2023-25912MEDIUM5.3The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that disc...
CVE-2023-25911HIGH8.8The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web ap...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now