2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-25564HIGH8.2GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, mem...
CVE-2023-25563HIGH7.5GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, mul...
CVE-2023-22943MEDIUM5.3In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to th...
CVE-2023-22942MEDIUM4.3In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a cross-site request forgery in the Splunk Secure Gateway...
CVE-2023-22941HIGH7.5In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Fiel...
CVE-2023-22940MEDIUM5.7In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL)...
CVE-2023-22939HIGH8.8In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a...
CVE-2023-22938MEDIUM4.3In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated ...
CVE-2023-22937MEDIUM4.3In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup ...
CVE-2023-22936MEDIUM6.3In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a ...
CVE-2023-22935HIGH8.8In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search par...
CVE-2023-22934HIGH8In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets...
CVE-2023-22933MEDIUM6.1In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extens...
CVE-2023-22932MEDIUM6.1In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scripting (XSS) through the error message i...
CVE-2023-22931MEDIUM4.3In Splunk Enterprise versions below 8.1.13 and 8.2.10, the ‘createrss’ external search command overwrites existing Resou...
CVE-2023-0830HIGH8.8A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /bac...
CVE-2023-25576HIGH7.5@fastify/multipart is a Fastify plugin to parse the multipart content-type. Prior to versions 7.4.1 and 6.0.1, @fastify/...
CVE-2023-24161CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in...
CVE-2023-24160CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in th...
CVE-2023-24159CRITICAL9.8TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in th...
CVE-2023-25149HIGH8.8TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through...
CVE-2023-25141HIGH7.5Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or e...
CVE-2023-0827MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 1.5.17.
CVE-2023-25065HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ShapedPlugin WP Tabs – Responsive Tabs Plugin for WordPress plugin <=...
CVE-2023-24382HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 ver...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now