2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-37507HIGH7.5HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon...
CVE-2023-54366HIGH8.8SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELE...
CVE-2023-37524HIGH7.8HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of servi...
CVE-2023-54365HIGH8.7Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri...
CVE-2023-45796HIGH8.1A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to an...
CVE-2023-45795HIGH7.8A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticat...
CVE-2023-54357HIGH8.7Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attacker...
CVE-2023-54353HIGH8.5Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attack...
CVE-2023-33999HIGH7.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Lo...
CVE-2023-43688HIGH7.5An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow i...
CVE-2023-29146HIGH8.2The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes trunca...
CVE-2023-54351HIGH7.2WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attac...
CVE-2023-54350HIGH8.7WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows ...
CVE-2023-5502HIGH8.2On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing en...
CVE-2023-52945HIGH7.8Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13...
CVE-2023-31317HIGH8.8Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an...
CVE-2023-31316HIGH7.1Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure P...
CVE-2023-27753HIGH8An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a c...
CVE-2023-42346HIGH7.5Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.
CVE-2023-42344HIGH7.3Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/...
CVE-2023-54348HIGH8.8ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to inject spreadsheet formulas...
CVE-2023-54347HIGH8.7OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protect...
CVE-2023-54346HIGH8.7WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated att...
CVE-2023-54345HIGH8.8Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated us...
CVE-2023-3634HIGH8.8In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of u...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now