2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28106MEDIUM4.8Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-s...
CVE-2023-28105HIGH8.8go-used-util has commonly used utility functions for Go. Versions prior to 0.0.34 have a ZipSlip issue when using fsutil...
CVE-2023-27041CRITICAL9.8School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/...
CVE-2023-28104HIGH7.5`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker cou...
CVE-2023-28101MEDIUM4.3Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior t...
CVE-2023-28100MEDIUM6.5Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1...
CVE-2023-27040CRITICAL9.8Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username paramet...
CVE-2023-28155MEDIUM6.1The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server tha...
CVE-2023-27789HIGH7.5An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the cidr2cidr function at th...
CVE-2023-27788HIGH7.5An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function a...
CVE-2023-27787HIGH7.5An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at t...
CVE-2023-27786HIGH7.5An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function.
CVE-2023-27785HIGH7.5An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoint...
CVE-2023-27784HIGH7.5An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring functio...
CVE-2023-27783HIGH7.5An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt...
CVE-2023-27711MEDIUM4.8Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the C...
CVE-2023-27709HIGH7.2SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_*...
CVE-2023-27707HIGH7.2SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_*...
CVE-2023-27131MEDIUM4.8Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code viathe Po...
CVE-2023-27130MEDIUM4.8Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an ar...
CVE-2023-27037HIGH8.8Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at ...
CVE-2023-26769HIGH7.5Buffer Overflow vulnerability found in Liblouis Lou_Trace v.3.24.0 allows a remote attacker to cause a denial of service...
CVE-2023-26768HIGH7.5Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the c...
CVE-2023-26767HIGH7.5Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the l...
CVE-2023-27875HIGH7.5IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Fo...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now