2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-46157HIGH8.8File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by c...
CVE-2023-32460HIGH7.8 Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker...
CVE-2023-26158HIGH8.2All versions of the package mockjs are vulnerable to Prototype Pollution via the Util.extend function due to missing che...
CVE-2023-48122HIGH7.5An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTT...
CVE-2023-43305HIGH8.2An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of...
CVE-2023-43744HIGH7.2An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware version...
CVE-2023-43743HIGH8.8A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior ...
CVE-2023-5058HIGH7.8Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Tec...
CVE-2023-4122HIGH8.8Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-pr...
CVE-2023-6580HIGH8.8A vulnerability, which was classified as critical, was found in D-Link DIR-846 FW100A53DBR. This affects an unknown part...
CVE-2023-6576HIGH8.8A vulnerability was found in Byzoro S210 up to 20231123. It has been declared as critical. This vulnerability affects un...
CVE-2023-6575HIGH8.8A vulnerability was found in Byzoro S210 up to 20231121. It has been classified as critical. This affects an unknown par...
CVE-2023-6574HIGH8.8A vulnerability was found in Byzoro Smart S20 up to 20231120 and classified as critical. Affected by this issue is some ...
CVE-2023-4486HIGH7.5Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls ...
CVE-2023-49468HIGH8.8Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at sl...
CVE-2023-49467HIGH8.8Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merg...
CVE-2023-49465HIGH8.8Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_predic...
CVE-2023-49464HIGH8.8libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::get_luma_bit...
CVE-2023-49463HIGH8.8libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc.
CVE-2023-49462HIGH8.8libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc.
CVE-2023-49460HIGH8.8libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::decode_uncom...
CVE-2023-39909HIGH8.8Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access t...
CVE-2023-33413HIGH8.8The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller ...
CVE-2023-33412HIGH8.8The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implemen...
CVE-2023-33411HIGH7.5A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementatio...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now