2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-34223MEDIUM5.3In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some c...
CVE-2023-34222MEDIUM6.1In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible
CVE-2023-34221MEDIUM5.4In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
CVE-2023-34220MEDIUM5.4In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
CVE-2023-34219MEDIUM4.3In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Bu...
CVE-2023-34218CRITICAL9.8In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
CVE-2023-31548MEDIUM5.4A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attac...
CVE-2023-26842MEDIUM5.4A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web scr...
CVE-2023-3009MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
CVE-2023-33736MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Dcat-Admin v2.1.3-beta allows attackers to execute arbitrary web sc...
CVE-2023-33509CRITICAL9.8KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection.
CVE-2023-33508CRITICAL9.8KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).
CVE-2023-33507HIGH7.5KramerAV VIA GO² < 4.0.1.1326 is vulnerable to Unauthenticated arbitrary file read.
CVE-2023-33487CRITICAL9.8TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagn...
CVE-2023-33486CRITICAL9.8TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpMode...
CVE-2023-33485HIGH8.8TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via par...
CVE-2023-3008CRITICAL9.8A vulnerability classified as critical has been found in ningzichun Student Management System 1.0. This affects an unkno...
CVE-2023-3007CRITICAL9.8A vulnerability was found in ningzichun Student Management System 1.0. It has been rated as critical. Affected by this i...
CVE-2023-30285HIGH7.5An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a us...
CVE-2023-2909CRITICAL10EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory st...
CVE-2023-3005MEDIUM6.1A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management...
CVE-2023-3004CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Simple Chat System 1.0. Affected by ...
CVE-2023-3003CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Train Station Ticketing System 1.0. Affected by this ...
CVE-2023-2749HIGH7.5Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability...
CVE-2023-2304MEDIUM5.4The Favorites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_favorites' shortcode in ve...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now