2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-30590HIGH7.5The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, th...
CVE-2023-40056HIGH8.8 SQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be expl...
CVE-2023-48848HIGH7.5An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server ...
CVE-2023-49062HIGH7.5Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulatio...
CVE-2023-46589HIGH7.5Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 throug...
CVE-2023-49314HIGH7.8Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection ag...
CVE-2023-6239HIGH8.8Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specif...
CVE-2023-6201HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Comp...
CVE-2023-42004HIGH8.8IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute ...
CVE-2023-6151HIGH7.5Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided b...
CVE-2023-6150HIGH7.5Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided b...
CVE-2023-34054HIGH7.5 In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a u...
CVE-2023-34053HIGH7.5In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that m...
CVE-2023-4226HIGH8.8Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers wit...
CVE-2023-4225HIGH8.8Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers...
CVE-2023-4224HIGH8.8Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers ...
CVE-2023-4223HIGH8.8Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers...
CVE-2023-4222HIGH8.8Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to u...
CVE-2023-4221HIGH8.8Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to up...
CVE-2023-49075HIGH7.2The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introdu...
CVE-2023-6219HIGH7.2The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the...
CVE-2023-4398HIGH7.5An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ...
CVE-2023-30585HIGH7.5A vulnerability has been identified in the Node.js (.msi version) installation process, specifically affecting Windows u...
CVE-2023-29770HIGH8.8In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file w...
CVE-2023-49030HIGH7.5SQL Injection vulnerability in32ns KLive v.2019-1-19 and before allows a remote attacker to obtain sensitive information...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now