2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32097HIGH7.5 Compiler removal of buffer clearing in sli_crypto_transparent_aead_decrypt_tag in Silicon Labs Gecko Platform...
CVE-2023-32096HIGH7.5 Compiler removal of buffer clearing in sli_crypto_transparent_aead_encrypt_tag in Silicon Labs Gecko Platform...
CVE-2023-30333CRITICAL9.8An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attacke...
CVE-2023-2481HIGH7.5 Compiler removal of buffer clearing in sli_se_opaque_import_key in Silicon Labs Gecko Platform SDK v4.2.1 and ea...
CVE-2023-1132HIGH7.5 Compiler removal of buffer clearing in sli_se_driver_key_agreement in Silicon Labs Gecko Platform SDK v4.2.1 and ea...
CVE-2023-0965HIGH7.5 Compiler removal of buffer clearing in sli_cryptoacc_transparent_key_agreement in Silicon Labs Gecko Platform SDK v4.2....
CVE-2023-31597MEDIUM6.5An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the d...
CVE-2023-32322MEDIUM4.9Ombi is an open source application which allows users to request specific media from popular self-hosted streaming serve...
CVE-2023-31871HIGH7.8OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Doc...
CVE-2023-2800MEDIUM4.7Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0.
CVE-2023-2799CRITICAL9.8A vulnerability, which was classified as problematic, has been found in cnoa OA up to 5.1.1.5. Affected by this issue is...
CVE-2023-2790MEDIUM5.5A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknow...
CVE-2023-2789HIGH7.5A vulnerability was found in GNU cflow 1.7. It has been rated as problematic. This issue affects the function func_body/...
CVE-2023-30780MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TheGuideX User IP and Location plugin <= 2.2 ver...
CVE-2023-2782MEDIUM5.5Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infra...
CVE-2023-27430HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Mass Delete Unused Tags plugin <= 2.0.0 versions.
CVE-2023-27423HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Auto Prune Posts plugin <= 1.8.0 versions.
CVE-2023-25698HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Studio Wombat Shoppable Images plugin <= 1.2.3 versions.
CVE-2023-23999MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions.
CVE-2023-23667MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in BeRocket Brands for WooCommerce plugin <= 3.7.0....
CVE-2023-32515MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matt Gibbs Custom Field Suite plugin <= 2.6.2.1 versio...
CVE-2023-31233MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Haoqisir Baidu Tongji generator plugin <= 1.0.2 versio...
CVE-2023-30868MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 version...
CVE-2023-30487MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThimPress LearnPress Export Import plugin <= 4.0.2 version...
CVE-2023-28369LOW3.3Brother iPrint&Scan V6.11.2 and earlier contains an improper access control vulnerability. This vulnerability may be exp...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now