2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-51949HIGH8.8Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/back...
CVE-2023-49261HIGH7.5The "tokenKey" value used in user authorization is visible in the HTML source of the login page.
CVE-2023-49259HIGH7.5The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and...
CVE-2023-49257HIGH8.8An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execut...
CVE-2023-49256HIGH7.5It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded...
CVE-2023-49254HIGH8.8Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destinati...
CVE-2023-5356HIGH8.8Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting...
CVE-2023-0437HIGH7.5When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an i...
CVE-2023-49568HIGH7.5A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an a...
CVE-2023-48909HIGH8.8An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function.
CVE-2023-6740HIGH7.8Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user t...
CVE-2023-6735HIGH7.8Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escal...
CVE-2023-34061HIGH7.5Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated att...
CVE-2023-6040HIGH7.8An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables:...
CVE-2023-40250HIGH8.8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows O...
CVE-2023-46474HIGH7.2File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a c...
CVE-2023-50123HIGH8.1The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. This co...
CVE-2023-51782HIGH7An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because ...
CVE-2023-51781HIGH7An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free becaus...
CVE-2023-51780HIGH7An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because o...
CVE-2023-50671HIGH7.8In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write ...
CVE-2023-51749HIGH8.8ScaleFusion 10.5.2 does not properly limit users to the Edge application because a search can be made from a tooltip. NO...
CVE-2023-51748HIGH8.8ScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is ...
CVE-2023-50159HIGH8.8In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrar...
CVE-2023-6979HIGH8.8The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now