2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-37185HIGH7.5C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_prec_decompress at zfp/b...
CVE-2023-28872HIGH8.8Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privile...
CVE-2023-51772HIGH8.8One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Direct...
CVE-2023-49328HIGH7.2On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated syst...
CVE-2023-31455HIGH7.5Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.
CVE-2023-31289HIGH7.5Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.
CVE-2023-49880HIGH7.5In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending...
CVE-2023-43064HIGH7.8Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqual...
CVE-2023-7094HIGH7.5A vulnerability classified as problematic was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected by th...
CVE-2023-7093HIGH7.8A vulnerability classified as critical has been found in KylinSoft kylin-system-updater up to 2.0.5.16-0k2.33. Affected ...
CVE-2023-7101HIGH7.8Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerabl...
CVE-2023-7091HIGH8.8A vulnerability was found in Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown ...
CVE-2023-51767HIGH7OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) bec...
CVE-2023-7090HIGH8.8A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated...
CVE-2023-5961HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and...
CVE-2023-7002HIGH7.2The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1....
CVE-2023-51650HIGH7.5Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration i...
CVE-2023-51449HIGH7.5Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine lear...
CVE-2023-51387HIGH8.8Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. Th...
CVE-2023-50730HIGH7.5Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification require...
CVE-2023-50714HIGH8.8yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. ...
CVE-2023-51662HIGH7.5The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing appl...
CVE-2023-51448HIGH8.8Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi)...
CVE-2023-50254HIGH7.8Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior t...
CVE-2023-49085HIGH8.8Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now