2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-0801MEDIUM5.5LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and too...
CVE-2023-0800MEDIUM5.5LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-s...
CVE-2023-0799MEDIUM5.5LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3701, allowing attackers to cause a denial-of-se...
CVE-2023-0798MEDIUM5.5LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3400, allowing attackers to cause a denial-of-se...
CVE-2023-0797MEDIUM5.5LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tool...
CVE-2023-0796MEDIUM5.5LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3592, allowing attackers to cause a denial-of-se...
CVE-2023-0795MEDIUM5.5LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3488, allowing attackers to cause a denial-of-se...
CVE-2023-0518HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions start...
CVE-2023-0819HIGH7.8Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV.
CVE-2023-0818MEDIUM5.5Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.
CVE-2023-0817HIGH7.8Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.
CVE-2023-25572MEDIUM5.4react-admin is a frontend framework for building browser applications on top of REST/GraphQL APIs. react-admin prior to ...
CVE-2023-25241MEDIUM6.1bgERP v22.31 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
CVE-2023-25240HIGH8.8An improper SameSite Attribute vulnerability in pimCore v10.5.15 allows attackers to execute arbitrary code.
CVE-2023-25162MEDIUM5.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior ...
CVE-2023-25161MEDIUM5.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Ne...
CVE-2023-25160MEDIUM5.3Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11...
CVE-2023-24648MEDIUM6.1Zstore v6.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php.
CVE-2023-24647HIGH7.5Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter.
CVE-2023-24646CRITICAL9.8An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attacker...
CVE-2023-24086MEDIUM6.1SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/l...
CVE-2023-24084CRITICAL9.8ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.
CVE-2023-25719HIGH8.8ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such ...
CVE-2023-25718CRITICAL9.8In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additio...
CVE-2023-25717CRITICAL9.8Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now