2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29125HIGH8A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.
CVE-2023-29122MEDIUM6.7Under certain conditions, access to service libraries is granted to account they should not have access to.
CVE-2023-29121HIGH8.8Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.
CVE-2023-29120HIGH8.8Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s priv...
CVE-2023-29119HIGH8.8Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.ph...
CVE-2023-29118HIGH8.8Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.p...
CVE-2023-29117HIGH8.8Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox...
CVE-2023-29116MEDIUM4.3Under certain conditions, through a request directed to the Waybox Enel X web management application, information like W...
CVE-2023-29115MEDIUM6.5In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service...
CVE-2023-29114MEDIUM5.7System logs could be accessed through web management application due to a lack of access control. An attacker can obta...
CVE-2023-52920MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: support non-r10 register spill/fill to/from st...
CVE-2023-34445MEDIUM6.1Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible f...
CVE-2023-34444MEDIUM6.1Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possib...
CVE-2023-34443MEDIUM6.1Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (X...
CVE-2023-52045MEDIUM6.1Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vuln...
CVE-2023-52044CRITICAL9.8Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files wi...
CVE-2023-52066HIGH7.2http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter.
CVE-2023-5816MEDIUM4.9The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and inclu...
CVE-2023-26248MEDIUM5.3The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information fo...
CVE-2023-50355MEDIUM5.3HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information t...
CVE-2023-50310HIGH7.5IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 transmits or stores authentication credentials, but it uses ...
CVE-2023-52919MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix possible NULL pointer dereference in ...
CVE-2023-52918MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: pci: cx23885: check cx23885_vdev_init() retu...
CVE-2023-52917Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-6243MEDIUM4.3The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forge...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now