2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-6893HIGH7.5A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as proble...
CVE-2023-6891HIGH7.8A vulnerability has been found in PeaZip 9.4.0 and classified as problematic. Affected by this vulnerability is an unkno...
CVE-2023-50784HIGH7.5A buffer overflow in websockets in UnrealIRCd 6.1.0 through 6.1.3 before 6.1.4 allows an unauthenticated remote attacker...
CVE-2023-39340HIGH7.5A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific reque...
CVE-2023-50728HIGH7.5octokit/webhooks is a GitHub webhook events toolset for Node.js. Starting in 9.26.0 and prior to 9.26.3, 10.9.2, 11.1.2,...
CVE-2023-50265HIGH7.5Bazarr manages and downloads subtitles. Prior to 1.3.1, the /api/swaggerui/static endpoint in bazarr/app/ui.py does not ...
CVE-2023-50264HIGH7.5Bazarr manages and downloads subtitles. Prior to 1.3.1, Bazarr contains an arbitrary file read in /system/backup/downloa...
CVE-2023-50723HIGH8.8XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone...
CVE-2023-50722HIGH8.8XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there ...
CVE-2023-50721HIGH8.8XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, t...
CVE-2023-50719HIGH7.5XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-...
CVE-2023-6680HIGH8.1An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior...
CVE-2023-49749HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in SureTriggers SureTriggers – Connect All Your Plugins, Apps, Tools & A...
CVE-2023-49744HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Gift Up Gift Up Gift Cards for WordPress and WooCommerce.This issue a...
CVE-2023-49197HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Apasionados, Apasionados del Marketing, NetConsulting DoFollow Case b...
CVE-2023-49159HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in Elegant Digital Solutions CommentLuv.This issue affects CommentLuv: ...
CVE-2023-3904HIGH7.5An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5...
CVE-2023-50870HIGH8.8In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible
CVE-2023-46116HIGH8.8Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applicati...
CVE-2023-49898HIGH7.2In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on t...
CVE-2023-33217HIGH7.5 By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent ...
CVE-2023-6837HIGH8.2Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order...
CVE-2023-6836HIGH7.5Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely ava...
CVE-2023-48394HIGH8.8Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file wit...
CVE-2023-48389HIGH7.5Multisuns EasyLog web+ has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated rem...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now