2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-41920CRITICAL9.8The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the devic...
CVE-2023-41919CRITICAL9.8Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauth...
CVE-2023-41918CRITICAL10A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this...
CVE-2023-41917CRITICAL10Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit thi...
CVE-2023-43554HIGH7.8Memory corruption while processing IOCTL handler in FastRPC.
CVE-2023-50964MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2023-50953MEDIUM4.3IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec...
CVE-2023-50952MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authentica...
CVE-2023-50954MEDIUM5.3IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further at...
CVE-2023-35022LOW3.3IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorizati...
CVE-2023-4017MEDIUM6.1The Goya theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attra-color’, 'attra-size', and '...
CVE-2023-47803MEDIUM5.3A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the...
CVE-2023-47802HIGH7.2A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is ...
CVE-2023-52892HIGH7.5In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields...
CVE-2023-38370MEDIUM6.5IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the ne...
CVE-2023-38368MEDIUM5.5IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do ...
CVE-2023-30998HIGH7.8IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to impro...
CVE-2023-30997HIGH7.8IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to impro...
CVE-2023-42014MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.2.0.2 is vulnerable to cross-site scripting. This vulnera...
CVE-2023-42011MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 6.1 and 6.2 does not restrict or incorrectly restricts frame objects or UI ...
CVE-2023-38371HIGH7.5IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 uses weaker than expected cryptographic algorithms that cou...
CVE-2023-30430MEDIUM5.5IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from trace l...
CVE-2023-7270MEDIUM5.3An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision...
CVE-2023-26877MEDIUM6.3File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .p...
CVE-2023-37541MEDIUM4.3HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now