2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-1714HIGH8.8Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote au...
CVE-2023-1713HIGH8.8Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apa...
CVE-2023-4197HIGH8.8Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when c...
CVE-2023-5899HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5898HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5897HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1.
CVE-2023-5893HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5889HIGH8.2Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-3955HIGH8.8A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalat...
CVE-2023-3676HIGH8.8A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalat...
CVE-2023-45955HIGH7.5An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write bind...
CVE-2023-37832HIGH7.5A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute forc...
CVE-2023-5739HIGH7.8Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.
CVE-2023-46723HIGH7.5lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use `sendto.txt` are vulnerable t...
CVE-2023-46248HIGH8.8Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 ar...
CVE-2023-46245HIGH7.2Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Templ...
CVE-2023-46240HIGH7.5CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a d...
CVE-2023-46239HIGH7.5quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by seri...
CVE-2023-46992HIGH7.5TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral ...
CVE-2023-46236HIGH7.5FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-si...
CVE-2023-42658HIGH7.8 Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profi...
CVE-2023-40050HIGH8.8Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec...
CVE-2023-37243HIGH7.8The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM w...
CVE-2023-5098HIGH8.1The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like s...
CVE-2023-46978HIGH7.5TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WI...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now