2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27238CRITICAL9.8LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning.
CVE-2023-27237MEDIUM6.1LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack.
CVE-2023-23169MEDIUM6.5Synapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal.
CVE-2023-2678MEDIUM5.4A vulnerability has been found in SourceCodester File Tracker Manager System 1.0 and classified as problematic. This vul...
CVE-2023-2677HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Covid-19 Contact Tracing System 1.0. This...
CVE-2023-2676CRITICAL9.8A vulnerability, which was classified as critical, has been found in H3C R160 V1004004. Affected by this issue is some u...
CVE-2023-2672CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Lost and Found Information System 1.0. Affected ...
CVE-2023-2671MEDIUM6.1A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been rated as problematic. Thi...
CVE-2023-2515HIGH8.8Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from eleva...
CVE-2023-2514HIGH7.5Mattermost Sever fails to redact the DB username and password before emitting an application log during server initializ...
CVE-2023-32243CRITICAL9.8Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This is...
CVE-2023-2674MEDIUM4.3Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2670HIGH8.8A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been declared as critical. Thi...
CVE-2023-2669CRITICAL9.8A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been classified as critical. T...
CVE-2023-29246HIGH7.2An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Softwa...
CVE-2023-29032HIGH8.1An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache...
CVE-2023-28936MEDIUM5.3Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeet...
CVE-2023-2668CRITICAL9.8A vulnerability was found in SourceCodester Lost and Found Information System 1.0 and classified as critical. Affected b...
CVE-2023-2667MEDIUM6.1A vulnerability has been found in SourceCodester Lost and Found Information System 1.0 and classified as problematic. Af...
CVE-2023-2511Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-2510Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-2502Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-2501Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-2185Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2023-0387Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now