2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-28793HIGH7.8Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. Th...
CVE-2023-5246HIGH8.8Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074,...
CVE-2023-43622HIGH7.5An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection...
CVE-2023-31122HIGH7.5Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.5...
CVE-2023-46324HIGH7.5pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may...
CVE-2023-46319HIGH7.5WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassi...
CVE-2023-46317HIGH7.5Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.
CVE-2023-46315HIGH7.5The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-...
CVE-2023-46095HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole Smooth Scroll Links [SSL] plugin <= 1.1.0 versions.
CVE-2023-46089HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Lee Le @ Userback Userback plugin <= 1.0.13 versions.
CVE-2023-46085HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.
CVE-2023-46303HIGH7.5link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources ou...
CVE-2023-46298HIGH7.5Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached ...
CVE-2023-38276HIGH7.5IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid...
CVE-2023-38275HIGH7.5IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to ...
CVE-2023-46078HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in PluginEver WC Serial Numbers plugin <= 1.6.3 versions.
CVE-2023-46067HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Qwerty23 Rocket Font plugin <= 1.2.3 versions.
CVE-2023-46055HIGH8.8An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a cra...
CVE-2023-5132HIGH7.5The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit...
CVE-2023-38193HIGH8.8An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command l...
CVE-2023-38190HIGH8.8An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.
CVE-2023-45682HIGH7.1stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of boun...
CVE-2023-45681HIGH7.8stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory writ...
CVE-2023-45679HIGH7.8stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allo...
CVE-2023-45678HIGH7.8stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of buff...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now