2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-23602MEDIUM6.5A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src head...
CVE-2023-23601MEDIUM6.5Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to webs...
CVE-2023-23600MEDIUM6.5Per origin notification permissions were being stored in a way that didn't take into account what browsing context the p...
CVE-2023-23599MEDIUM6.5When copying a network request from the developer tools panel as a curl command the output was not being properly saniti...
CVE-2023-23598MEDIUM6.5Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing f...
CVE-2023-23597MEDIUM6.5A compromised web child process could disable web security opening restrictions, leading to a new child process being sp...
CVE-2023-1945MEDIUM6.5Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable cr...
CVE-2023-0767HIGH8.8An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12...
CVE-2023-0616MEDIUM6.5If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and d...
CVE-2023-0547MEDIUM6.5OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certif...
CVE-2023-0430MEDIUM6.5Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certific...
CVE-2023-3068CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Retro Cellphone Online Store 1.0. Affected is an unkn...
CVE-2023-3067MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4.
CVE-2023-34094MEDIUM5.3ChuanhuChatGPT is a graphical user interface for ChatGPT and many large language models. A vulnerability in versions 202...
CVE-2023-2687LOW3.3Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited ...
CVE-2023-30149CRITICAL9.8SQL injection vulnerability in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop, prior to v...
CVE-2023-3062CRITICAL9.8A vulnerability was found in code-projects Agro-School Management System 1.0. It has been classified as critical. Affect...
CVE-2023-3061CRITICAL9.8A vulnerability was found in code-projects Agro-School Management System 1.0 and classified as critical. This issue affe...
CVE-2023-3060MEDIUM5.4A vulnerability has been found in code-projects Agro-School Management System 1.0 and classified as problematic. This vu...
CVE-2023-34362CRITICAL9.8In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023....
CVE-2023-33476CRITICAL9.8ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by ...
CVE-2023-3059CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Online Exam Form Submission 1.0. This aff...
CVE-2023-3058MEDIUM5.4A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unkn...
CVE-2023-3057CRITICAL9.8A vulnerability was found in YFCMF up to 3.0.4. It has been rated as problematic. This issue affects some unknown proces...
CVE-2023-3033HIGH8.8Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Co...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now