2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29752HIGH7.8An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows unauthorized apps to cause escalation of privileg...
CVE-2023-29749HIGH7.8An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause escalation of privilege attacks ...
CVE-2023-2455MEDIUM5.4Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied...
CVE-2023-2454HIGH7.2schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could perm...
CVE-2023-29714MEDIUM6.1Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via t...
CVE-2023-29713MEDIUM6.1Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a...
CVE-2023-27706HIGH7.1Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, ac...
CVE-2023-34245MEDIUM6.1@udecode/plate-link is the link handler for the udecode/plate rich-text editor plugin system for Slate & React. Affected...
CVE-2023-34100MEDIUM6.5Contiki-NG is an open-source, cross-platform operating system for IoT devices. When reading the TCP MSS option value fro...
CVE-2023-33557HIGH8.8Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.
CVE-2023-30262HIGH8.8An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a r...
CVE-2023-29712MEDIUM6.1Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a...
CVE-2023-2121MEDIUM5.4Vault and Vault Enterprise's (Vault) key-value v2 (kv-v2) diff viewer allowed HTML injection into the Vault web UI throu...
CVE-2023-3184MEDIUM4.8A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affec...
CVE-2023-3183MEDIUM5.4A vulnerability was found in SourceCodester Performance Indicator System 1.0. It has been declared as problematic. Affec...
CVE-2023-2286MEDIUM4.3The WP Activity Log for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.0. T...
CVE-2023-2285MEDIUM4.3The WP Activity Log Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl...
CVE-2023-2284MEDIUM4.3The WP Activity Log Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2023-2261MEDIUM4.3The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ...
CVE-2023-32732MEDIUM5.3gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC se...
CVE-2023-32731HIGH7.5When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused a...
CVE-2023-1428HIGH7.5There exists an vulnerability causing an abort() to be called in gRPC.  The following headers cause gRPC's C++ implement...
CVE-2023-0342MEDIUM5.3MongoDB Ops Manager Diagnostics Archive may not redact sensitive PEM key file password app settings. Archives do not inc...
CVE-2023-34364CRITICAL9.8A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large v...
CVE-2023-34363MEDIUM5.9An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. When using Oracle Advanced...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now