2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6080HIGH7.8Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnera...
CVE-2023-49570HIGH7.4A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts...
CVE-2023-6058MEDIUM6.8A vulnerability has been identified in Bitdefender Safepay's handling of HTTPS connections. The issue arises when the pr...
CVE-2023-6057HIGH7.4A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the impro...
CVE-2023-6056HIGH7.4A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the impro...
CVE-2023-6055HIGH7.4A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails ...
CVE-2023-49567MEDIUM6.8A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product inc...
CVE-2023-39593MEDIUM5.6Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary comma...
CVE-2023-26785CRITICAL9.8MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File...
CVE-2023-6729HIGH7.3Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access ...
CVE-2023-6728LOW3.3Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This weakness allows an attacker in possessio...
CVE-2023-32266MEDIUM5.3Untrusted Search Path vulnerability in OpenText™ Application Lifecycle Management (ALM),Quality Center allows Code Inclu...
CVE-2023-32189MEDIUM6.4Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys
CVE-2023-32196HIGH7.5A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobject...
CVE-2023-32194HIGH8.6A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matt...
CVE-2023-32193HIGH8.3A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint...
CVE-2023-32192HIGH8.3A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API ...
CVE-2023-32191CRITICAL9.9When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-s...
CVE-2023-32190HIGH8.5mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file opera...
CVE-2023-32188CRITICAL9.4A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a ...
CVE-2023-22650HIGH8.8A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from ...
CVE-2023-7296MEDIUM6.4The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewe...
CVE-2023-7295MEDIUM6.1The Video Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in ver...
CVE-2023-22649MEDIUM6.5A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Au...
CVE-2023-7294MEDIUM6.5The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now