2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-26300HIGH7.8A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow e...
CVE-2023-45912HIGH7.5WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers ...
CVE-2023-30911HIGH7.5HPE Integrated Lights-Out 5, and Integrated Lights-Out 6 using iLOrest may cause denial of service.
CVE-2023-46009HIGH7.8gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c.
CVE-2023-45383HIGH7.5In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest c...
CVE-2023-43250HIGH7.8XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attacker...
CVE-2023-46004HIGH7.2Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function.
CVE-2023-45727HIGH7.5Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail S...
CVE-2023-5632HIGH7.5In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data c...
CVE-2023-42319HIGH7.5Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of servi...
CVE-2023-39331HIGH7.5A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path travers...
CVE-2023-38552HIGH7.5When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can inter...
CVE-2023-5626HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16.
CVE-2023-5552HIGH7.5A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to ...
CVE-2023-45811HIGH7.8Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions...
CVE-2023-45810HIGH7.5OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected ver...
CVE-2023-42507HIGH7.8Stack-based buffer overflow vulnerability exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is expl...
CVE-2023-42506HIGH7.8Improper restriction of operations within the bounds of a memory buffer issue exists in OnSinView2 versions 2.0.1 and ea...
CVE-2023-41715HIGH8.8SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to el...
CVE-2023-41713HIGH7.5SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.
CVE-2023-36321HIGH7.5Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflow via the component ...
CVE-2023-41631HIGH8.8eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload funct...
CVE-2023-41629HIGH7.5A lack of input sanitizing in the file download feature of eSST Monitoring v2.147.1 allows attackers to execute a path t...
CVE-2023-22108HIGH7.5Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2023-22102HIGH8.3Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are aff...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now