2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2201HIGH8.8The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and i...
CVE-2023-29746CRITICAL9.8An issue found in The Thaiger v.1.2 for Android allows unauthorized apps to cause a code execution attack by manipulatin...
CVE-2023-29725MEDIUM5.5The BT21 x BTS Wallpaper app 12 for Android allows unauthorized applications to actively request permission to insert da...
CVE-2023-29724HIGH7.8The BT21 x BTS Wallpaper app 12 for Android allows unauthorized apps to actively request permission to modify data in th...
CVE-2023-27745HIGH8.8An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform A...
CVE-2023-27744HIGH7.8An issue was discovered in South River Technologies TitanFTP NextGen server that allows for a vertical privilege escalat...
CVE-2023-28147MEDIUM5.5An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat...
CVE-2023-29736CRITICAL9.8Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to o...
CVE-2023-29723HIGH7.5The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized applications to actively request permissi...
CVE-2023-29722CRITICAL9.1The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized apps to actively request permission to mo...
CVE-2023-27640HIGH7.5An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req...
CVE-2023-27639HIGH7.5An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req...
CVE-2023-33764MEDIUM5.4eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a stored cross-site scripting (XSS) vulnerabil...
CVE-2023-33754MEDIUM6.5The captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts fo...
CVE-2023-34339LOW3.3In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message
CVE-2023-34092HIGH7.5Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`s...
CVE-2023-34091MEDIUM6.5Kyverno is a policy engine designed for Kubernetes. In versions of Kyverno prior to 1.10.0, resources which have the `de...
CVE-2023-33960HIGH7.5OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated...
CVE-2023-32717MEDIUM4.3On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100,...
CVE-2023-32716MEDIUM6.5In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, an...
CVE-2023-32715MEDIUM6.1In the Splunk App for Lookup File Editing versions below 4.0.1, a user can insert potentially malicious JavaScript code ...
CVE-2023-32714HIGH8.1In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web ...
CVE-2023-32713CRITICAL9.9In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process ...
CVE-2023-32712LOW3.1In Splunk Enterprise versions below 9.1.0.2, 9.0.5.1, and 8.2.11.2, an attacker can inject American National Standards I...
CVE-2023-32711MEDIUM5.4In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, a Splunk dashboard view lets a low-privileged user exploi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now