2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-37508 | MEDIUM | 6.1 | 0.2% | Jul 21, 2026 | HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this v... |
| CVE-2023-20572 | MEDIUM | 5.6 | — | Jun 26, 2026 | An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against th... |
| CVE-2023-33854 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow a... |
| CVE-2023-32959 | MEDIUM | 4.3 | 0.2% | Jun 11, 2026 | Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access ... |
| CVE-2023-25969 | MEDIUM | 5.4 | 0.2% | Jun 11, 2026 | Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectl... |
| CVE-2023-40200 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider an... |
| CVE-2023-43686 | MEDIUM | 6.2 | 0.1% | Jun 9, 2026 | An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox prefere... |
| CVE-2023-52951 | MEDIUM | 5.9 | 0.1% | Jun 3, 2026 | A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows ... |
| CVE-2023-7346 | MEDIUM | 4.1 | 0.1% | May 20, 2026 | Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause i... |
| CVE-2023-7345 | MEDIUM | 6.9 | 0.3% | May 19, 2026 | Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability th... |
| CVE-2023-31309 | MEDIUM | 6.8 | 0.1% | May 15, 2026 | Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload... |
| CVE-2023-30059 | MEDIUM | 5.4 | 0.2% | May 12, 2026 | An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other use... |
| CVE-2023-47268 | MEDIUM | 5.3 | 0.7% | May 8, 2026 | In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar... |
| CVE-2023-42345 | MEDIUM | 6.1 | 0.1% | May 8, 2026 | A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp. |
| CVE-2023-42343 | MEDIUM | 6.1 | 0.6% | May 8, 2026 | A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type. |
| CVE-2023-54349 | MEDIUM | 6.1 | 0.3% | May 5, 2026 | AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject... |
| CVE-2023-20585 | MEDIUM | 5.6 | 0.1% | Apr 16, 2026 | Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hy... |
| CVE-2023-5872 | MEDIUM | 4.3 | 0.3% | Apr 16, 2026 | In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames th... |
| CVE-2023-54364 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to i... |
| CVE-2023-54363 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to ... |
| CVE-2023-54362 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to ... |
| CVE-2023-54361 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inje... |
| CVE-2023-54360 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicio... |
| CVE-2023-54358 | MEDIUM | 6.1 | 0.3% | Apr 9, 2026 | WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated ... |
| CVE-2023-7340 | MEDIUM | 4.3 | 0.3% | Mar 27, 2026 | Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now