2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-48631HIGH7.5@adobe/css-tools versions 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result...
CVE-2023-25644HIGH7.5 There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web ...
CVE-2023-25643HIGH8.8 There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation...
CVE-2023-1904HIGH7.5In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the...
CVE-2023-25651HIGH8 There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SM...
CVE-2023-25648HIGH7.8 There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attack...
CVE-2023-6407HIGH7.1 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that coul...
CVE-2023-49938HIGH8.2An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modifie...
CVE-2023-49936HIGH7.5An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. A NULL pointer dereference leads to denial of se...
CVE-2023-49935HIGH8.8An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Mess...
CVE-2023-49933HIGH7.5An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. There is Improper Enforcement of Message Integri...
CVE-2023-45184HIGH7.5IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryp...
CVE-2023-41720HIGH7.8A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Iva...
CVE-2023-41719HIGH7.2A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administ...
CVE-2023-43042HIGH7.5IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords f...
CVE-2023-45174HIGH7.8IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to ...
CVE-2023-45170HIGH7.8IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command t...
CVE-2023-45166HIGH7.8IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piodmgrsu comma...
CVE-2023-43586HIGH8.8Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an a...
CVE-2023-50709HIGH7.5Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cub...
CVE-2023-50262HIGH7.5Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Dompdf performs an initial validation to ensure that...
CVE-2023-48702HIGH7.2Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the `/System/MediaEncoder/Path` endpoin...
CVE-2023-6773HIGH8.8A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affec...
CVE-2023-50444HIGH7.5By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! fo...
CVE-2023-46247HIGH7.5Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Contracts containing large arrays mi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now