2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28009HIGH8.1HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remot...
CVE-2023-28008HIGH8.1HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processi...
CVE-2023-27559HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv...
CVE-2023-26567HIGH8.1Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPAS...
CVE-2023-31250MEDIUM6.5The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gain...
CVE-2023-30841MEDIUM5.5Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic an...
CVE-2023-30546HIGH7.5Contiki-NG is an operating system for Internet of Things devices. An off-by-one error can be triggered in the Antelope d...
CVE-2023-26938Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2019-9587. Reason: This record is a reservatio...
CVE-2023-26937Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2019-9587. Reason: This record is a reservatio...
CVE-2023-26936Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2019-9587. Reason: This record is a reservatio...
CVE-2023-26935Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2019-9587. Reason: This record is a reservatio...
CVE-2023-26934Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2019-9587. Reason: This record is a reservatio...
CVE-2023-26931Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2022-30524. Reason: This record is a duplicate of CVE-2022-...
CVE-2023-26930MEDIUM5.5Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc...
CVE-2023-0458MEDIUM4.7A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument...
CVE-2023-29268CRITICAL9.8The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that all...
CVE-2023-30212MEDIUM6.1OURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php.
CVE-2023-2307MEDIUM6.5Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.
CVE-2023-30211CRITICAL9.8OURPHP <= 7.2.0 is vulnerable to SQL Injection.
CVE-2023-30210MEDIUM6.1OURPHP <= 7.2.0 is vulnerable to Cross Site Scripting (XSS) via ourphp_tz.php.
CVE-2023-22729MEDIUM6.1Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Pr...
CVE-2023-30269HIGH8.1CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php.
CVE-2023-30267MEDIUM6.1CLTPHP <=6.0 is vulnerable to Cross Site Scripting (XSS) via application/home/controller/Changyan.php.
CVE-2023-30266HIGH8.8CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type.
CVE-2023-30265MEDIUM6.5CLTPHP <=6.0 is vulnerable to Directory Traversal.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now