2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2947MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2946HIGH8.1Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2945MEDIUM5.4Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2944MEDIUM5.4Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2943HIGH8.8Code Injection in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2942HIGH8.1Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-32695HIGH7.5socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol...
CVE-2023-2928HIGH8.8A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is ...
CVE-2023-2927CRITICAL9.8A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the f...
CVE-2023-2926MEDIUM6.5A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of th...
CVE-2023-2925MEDIUM5.4A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part...
CVE-2023-2924CRITICAL9.8A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. Affected by this ...
CVE-2023-2923CRITICAL9.8A vulnerability classified as critical was found in Tenda AC6 US_AC6V1.0BR_V15.03.05.19. Affected by this vulnerability ...
CVE-2023-2922MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Comment System 1.0. Affected is an unknown fu...
CVE-2023-33184MEDIUM5.3Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the s...
CVE-2023-26129HIGH7.8All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check'...
CVE-2023-26128HIGH7.8All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or ...
CVE-2023-26127HIGH7.8All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.e...
CVE-2023-33195MEDIUM6.1Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This...
CVE-2023-33192HIGH7.5ntpd-rs is an NTP implementation written in Rust. ntpd-rs does not validate the length of NTS cookies in received NTP pa...
CVE-2023-33188MEDIUM5.5Omni-notes is an open source note-taking application for Android. The Omni-notes Android app had an insufficient path va...
CVE-2023-32688HIGH7.5parse-server-push-adapter is the official Push Notification adapter for Parse Server. The Parse Server Push Adapter can ...
CVE-2023-32686MEDIUM5.4Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to uplo...
CVE-2023-32325MEDIUM6.1PostHog-js is a library to interface with the PostHog analytics tool. Versions prior to 1.57.2 have the potential for cr...
CVE-2023-33199MEDIUM5.3Rekor's goals are to provide an immutable tamper resistant ledger of metadata generated within a software projects suppl...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now