2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0766HIGH8.8The Newsletter Popup WordPress plugin through 1.2 does not have CSRF checks in some places, which could allow attackers ...
CVE-2023-0733MEDIUM6.1The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow u...
CVE-2023-0443MEDIUM5.3The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker ...
CVE-2023-0329HIGH7.2The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL param...
CVE-2023-33955MEDIUM5.3Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the orig...
CVE-2023-33191HIGH8.8Kyverno is a policy engine designed for Kubernetes. Kyverno seccomp control can be circumvented. Users of the podSecurit...
CVE-2023-33193CRITICAL9.1Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any for...
CVE-2023-33189CRITICAL9.8Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisio...
CVE-2023-33186MEDIUM6.1Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and ch...
CVE-2023-33183MEDIUM4.3Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the websi...
CVE-2023-2970MEDIUM6.5A vulnerability classified as problematic was found in MindSpore 2.0.0-alpha/2.0.0-rc1. This vulnerability affects the f...
CVE-2023-33245HIGH8.8Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution...
CVE-2023-33198HIGH7.5tgstation-server is a production scale tool for BYOND server management. The DreamMaker API (DMAPI) chat channel cache c...
CVE-2023-33182MEDIUM4.3Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsani...
CVE-2023-33175HIGH7.5ToUI is a Python package for creating user interfaces (websites and desktop apps) from HTML. ToUI is using Flask-Caching...
CVE-2023-32685MEDIUM5.4Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements und...
CVE-2023-26130HIGH8.8Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is ...
CVE-2023-34205CRITICAL9.1In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canon...
CVE-2023-34204MEDIUM6.5imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these ar...
CVE-2023-32698HIGH7.1nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packag...
CVE-2023-32692CRITICAL9.8CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you us...
CVE-2023-32691MEDIUM5.9gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys sh...
CVE-2023-27988HIGH7.2The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 ...
CVE-2023-32687MEDIUM6.5tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instanc...
CVE-2023-32072MEDIUM4.8Tuleap is an open source tool for end to end traceability of application and system developments. Tuleap Community Editi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now