2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-41102HIGH7.5An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not ...
CVE-2023-39548HIGH8.8CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP...
CVE-2023-39547HIGH8.8CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP...
CVE-2023-39546HIGH8.8CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP...
CVE-2023-39545HIGH8.8CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP...
CVE-2023-39544HIGH8.8CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXP...
CVE-2023-38322HIGH7.5An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference th...
CVE-2023-38320HIGH7.5An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer derefere...
CVE-2023-38315HIGH7.5An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer deref...
CVE-2023-38313HIGH7.5An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can b...
CVE-2023-47675HIGH7.2CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary ...
CVE-2023-38130HIGH8.1Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to d...
CVE-2023-45382HIGH7.5In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can downl...
CVE-2023-47687HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in VJInfotech Woo Custom and Sequential Order Number plugin <= 2.6.0 ver...
CVE-2023-47686HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.2.2 ve...
CVE-2023-47688HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Alexufo Youtube SpeedLoad plugin <= 0.6.3 versions.
CVE-2023-6020HIGH7.5LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
CVE-2023-46214HIGH8.8In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet la...
CVE-2023-48134HIGH7.5nagayama_copabowl Line 13.6.1 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor.
CVE-2023-48056HIGH7.5PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerabil...
CVE-2023-48055HIGH7.5SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the dis...
CVE-2023-48054HIGH7.4Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host...
CVE-2023-48053HIGH7.5Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerabilit...
CVE-2023-48052HIGH7.4Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and...
CVE-2023-6038HIGH7.5A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to re...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now