2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27247MEDIUM4.4Cynet Client Agent v4.6.0.8010 allows attackers with Administrator rights to disable the EDR functions by disabling proc...
CVE-2023-27246HIGH8.8An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary co...
CVE-2023-27821CRITICAL9.8Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter.
CVE-2023-0775MEDIUM6.5An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to ...
CVE-2023-27008MEDIUM6.1A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows r...
CVE-2023-26923HIGH7Musescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If a...
CVE-2023-0466MEDIUM5.3The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing ...
CVE-2023-0465MEDIUM5.3Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious C...
CVE-2023-27701HIGH8.1MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /database/sqldel.html.
CVE-2023-25260HIGH7.5Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.
CVE-2023-28326CRITICAL9.8Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Att...
CVE-2023-25197MEDIUM6.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Fo...
CVE-2023-25196MEDIUM4.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Fo...
CVE-2023-25195HIGH8.1Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with li...
CVE-2023-25704MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mehjabin Orthi Interactive SVG Image Map Builder plugi...
CVE-2023-27700HIGH8.1MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /accessory/picdel.html...
CVE-2023-25262HIGH7.5Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting D...
CVE-2023-23330HIGH7.5amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.
CVE-2023-28430HIGH8.1OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is tri...
CVE-2023-28102CRITICAL9.6discordrb is an implementation of the Discord API using Ruby. In discordrb before commit `91e13043ffa` the `encoder.rb` ...
CVE-2023-26924MEDIUM5.5LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the ...
CVE-2023-26549HIGH7.5The SystemUI module has a vulnerability of repeated app restart due to improper parameters. Successful exploitation of t...
CVE-2023-26548HIGH7.5The pgmng module has a vulnerability in serialization/deserialization. Successful exploitation of this vulnerability may...
CVE-2023-26547HIGH7.8The InputMethod module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vu...
CVE-2023-26493HIGH8.8Cocos Engine is an open-source framework for building 2D & 3D real-time rendering and interactive content. In the github...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now