2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32568HIGH7.2An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM...
CVE-2023-2616MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.
CVE-2023-26126MEDIUM5.3All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the pat...
CVE-2023-25833MEDIUM5.4There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, auth...
CVE-2023-31478HIGH7.5An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configurati...
CVE-2023-2610HIGH7.8Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.
CVE-2023-2156HIGH7.5A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue res...
CVE-2023-28318MEDIUM5.3A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory o...
CVE-2023-28317MEDIUM5.3A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing th...
CVE-2023-28316CRITICAL9.8A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other activ...
CVE-2023-28128HIGH7.2An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could...
CVE-2023-28127HIGH7.5A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible ...
CVE-2023-28126MEDIUM5.9An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain...
CVE-2023-28125MEDIUM5.9An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attack...
CVE-2023-30057MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in FICO Origination Manager Decision Module 4.8.1 allow attac...
CVE-2023-30056HIGH7.5A session takeover vulnerability exists in FICO Origination Manager Decision Module 4.8.1 due to insufficient protection...
CVE-2023-25832HIGH8.8There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an ...
CVE-2023-25831MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unau...
CVE-2023-20524HIGH7.5An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out ...
CVE-2023-20520CRITICAL9.8Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-b...
CVE-2023-31474HIGH7.5An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to in...
CVE-2023-31472HIGH7.5An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be ...
CVE-2023-2609MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.
CVE-2023-29343HIGH7.8SysInternals Sysmon for Windows Elevation of Privilege Vulnerability
CVE-2023-29341HIGH7.8AV1 Video Extension Remote Code Execution Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now