2023 CVE Vulnerabilities

31,440 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-20864CRITICAL9.8VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with netwo...
CVE-2023-27090MEDIUM5.4Cross Site Scripting vulnerability found in TeaCMS storage allows attacker to cause a leak of sensitive information via ...
CVE-2023-30076CRITICAL9.8Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges....
CVE-2023-23579HIGH7.8 Datakit CrossCadWare_x64.dll contains an out-of-bounds write past the end of an allocated buffer while parsing ...
CVE-2023-22846MEDIUM5.5 Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a s...
CVE-2023-22354MEDIUM5.5 Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a spe...
CVE-2023-22321MEDIUM5.5 Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a speci...
CVE-2023-22295MEDIUM5.5Datakit CrossCadWare_x64.dll contains an out of bounds read past the end of an allocated buffer while parsing a speciall...
CVE-2023-30616MEDIUM6.5Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-S...
CVE-2023-29528CRITICAL9XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTM...
CVE-2023-27495MEDIUM6.5@fastify/csrf-protection is a plugin which helps protect Fastify servers against CSRF attacks. The CSRF protection enfor...
CVE-2023-23938MEDIUM4.8Tuleap is a Free & Source tool for end to end traceability of application and system developments. Affected versions are...
CVE-2023-1255MEDIUM5.9Issue summary: The AES-XTS cipher decryption implementation for 64 bit ARM platform contains a bug that could cause it t...
CVE-2023-27351HIGH7.5This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui...
CVE-2023-27350CRITICAL9.8This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui...
CVE-2023-25601MEDIUM4.3On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attac...
CVE-2023-29926CRITICAL9.8PowerJob V4.3.2 has unauthorized interface that causes remote code execution.
CVE-2023-27652MEDIUM5.5An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of serv...
CVE-2023-22309MEDIUM6.1Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.
CVE-2023-1767MEDIUM5.4The Snyk Advisor website (https://snyk.io/advisor/) was vulnerable to a stored XSS prior to 28th March 2023. A feature o...
CVE-2023-2193CRITICAL9.1Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker posse...
CVE-2023-2112HIGH7.8Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
CVE-2023-0384HIGH7.5User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrol...
CVE-2023-0383HIGH7.5User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrol...
CVE-2023-28047HIGH7.8 Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during inst...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now