2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-46449HIGH8.8Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbit...
CVE-2023-46234HIGH7.5browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based...
CVE-2023-45868HIGH8.1The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high...
CVE-2023-5783HIGH7.5A vulnerability has been found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this vulnerability i...
CVE-2023-5802HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Mihai Iova WordPress Knowledge base & Documentation Plugin – WP Knowl...
CVE-2023-5798HIGH8.8The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_ge...
CVE-2023-5139HIGH7.8Potential buffer overflow vulnerability at the following location in the Zephyr STM32 Crypto driver
CVE-2023-31421HIGH7.5It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whe...
CVE-2023-31422HIGH7.5An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. Th...
CVE-2023-46667HIGH8.1An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into th...
CVE-2023-46345HIGH7.5Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c.
CVE-2023-43905HIGH7.5Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecifi...
CVE-2023-30967HIGH7.5Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unaut...
CVE-2023-38849HIGH7.5An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
CVE-2023-38848HIGH7.5An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET r...
CVE-2023-38847HIGH7.5An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET reque...
CVE-2023-38846HIGH7.5An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
CVE-2023-38845HIGH7.5An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via craf...
CVE-2023-5574HIGH7A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy confi...
CVE-2023-5367HIGH7.8A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buff...
CVE-2023-5044HIGH8.8Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
CVE-2023-5043HIGH8.8Ingress nginx annotation injection causes arbitrary command execution.
CVE-2023-45135HIGH8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In `org.xwiki.p...
CVE-2023-42856HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, ...
CVE-2023-42852HIGH8.8A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now