2023 CVE Vulnerabilities
31,442 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-1306 | HIGH | 8.8 | 1.2% | Mar 21, 2023 | An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jin... |
| CVE-2023-1305 | HIGH | 8.1 | 0.8% | Mar 21, 2023 | An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided tho... |
| CVE-2023-1304 | HIGH | 8.8 | 1.1% | Mar 21, 2023 | An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perfo... |
| CVE-2023-27570 | CRITICAL | 9.8 | 0.6% | Mar 21, 2023 | The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie. |
| CVE-2023-27569 | CRITICAL | 9.8 | 0.9% | Mar 21, 2023 | The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header. |
| CVE-2023-25923 | HIGH | 7.5 | 0.7% | Mar 21, 2023 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that... |
| CVE-2023-25686 | MEDIUM | 5.5 | 0.2% | Mar 21, 2023 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text ... |
| CVE-2023-27874 | HIGH | 8.8 | 1.3% | Mar 21, 2023 | IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot... |
| CVE-2023-27873 | MEDIUM | 6.5 | 0.8% | Mar 21, 2023 | IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using sp... |
| CVE-2023-27871 | HIGH | 7.5 | 0.9% | Mar 21, 2023 | IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, u... |
| CVE-2023-27842 | HIGH | 8.8 | 2.4% | Mar 21, 2023 | Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execut... |
| CVE-2023-25689 | MEDIUM | 5.3 | 0.7% | Mar 21, 2023 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse d... |
| CVE-2023-25687 | MEDIUM | 4.3 | 0.5% | Mar 21, 2023 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain ... |
| CVE-2023-27983 | MEDIUM | 5.3 | 0.4% | Mar 21, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could... |
| CVE-2023-27979 | MEDIUM | 6.5 | 0.2% | Mar 21, 2023 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the r... |
| CVE-2023-27977 | MEDIUM | 5.3 | 0.2% | Mar 21, 2023 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause acces... |
| CVE-2023-1314 | HIGH | 7.8 | 0.3% | Mar 21, 2023 | A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a l... |
| CVE-2023-1154 | MEDIUM | 6.1 | 0.4% | Mar 21, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pacsrapor allows R... |
| CVE-2023-1153 | CRITICAL | 9.8 | 0.7% | Mar 21, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows S... |
| CVE-2023-27984 | HIGH | 8.8 | 0.6% | Mar 21, 2023 | A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, pote... |
| CVE-2023-1545 | HIGH | 7.5 | 8.4% | Mar 21, 2023 | SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. |
| CVE-2023-27981 | HIGH | 8.8 | 0.7% | Mar 21, 2023 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could ... |
| CVE-2023-27978 | HIGH | 7.8 | 6.5% | Mar 21, 2023 | A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpreta... |
| CVE-2023-1462 | HIGH | 8.8 | 0.7% | Mar 21, 2023 | Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Aut... |
| CVE-2023-27982 | HIGH | 8.8 | 0.4% | Mar 21, 2023 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manip... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now