2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1306HIGH8.8An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jin...
CVE-2023-1305HIGH8.1An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided tho...
CVE-2023-1304HIGH8.8An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perfo...
CVE-2023-27570CRITICAL9.8The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.
CVE-2023-27569CRITICAL9.8The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
CVE-2023-25923HIGH7.5IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that...
CVE-2023-25686MEDIUM5.5IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text ...
CVE-2023-27874HIGH8.8IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot...
CVE-2023-27873MEDIUM6.5 IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using sp...
CVE-2023-27871HIGH7.5IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, u...
CVE-2023-27842HIGH8.8Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execut...
CVE-2023-25689MEDIUM5.3IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse d...
CVE-2023-25687MEDIUM4.3IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain ...
CVE-2023-27983MEDIUM5.3A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could...
CVE-2023-27979MEDIUM6.5A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the r...
CVE-2023-27977MEDIUM5.3A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause acces...
CVE-2023-1314HIGH7.8A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a l...
CVE-2023-1154MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pacsrapor allows R...
CVE-2023-1153CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows S...
CVE-2023-27984HIGH8.8A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, pote...
CVE-2023-1545HIGH7.5SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.
CVE-2023-27981HIGH8.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could ...
CVE-2023-27978HIGH7.8A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpreta...
CVE-2023-1462HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Aut...
CVE-2023-27982HIGH8.8A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manip...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now