2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-45354HIGH8.8Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated remote attac...
CVE-2023-45353HIGH8.8Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to ...
CVE-2023-45352HIGH8.8Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to ...
CVE-2023-45351HIGH8.8Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1....
CVE-2023-45350HIGH8.8Atos Unify OpenScape 4000 Manager V10 R1 before V10 R1.42.1 and 4000 Manager V10 R0 allow Privilege escalation that may ...
CVE-2023-45349HIGH7.5Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.34.7, 4000 Assistant V10 R1.42.0, 4000 Assistant V10 R0, 4000 M...
CVE-2023-40635HIGH7.8In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no add...
CVE-2023-40634HIGH7.8In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with...
CVE-2023-40632HIGH7.5In jpg driver, there is a possible use after free due to a logic error. This could lead to remote information disclosure...
CVE-2023-43615HIGH7.5Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
CVE-2023-36123HIGH7.8Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to ex...
CVE-2023-44860HIGH7.5An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization ...
CVE-2023-44061HIGH8.8File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary co...
CVE-2023-45303HIGH8.8ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because A...
CVE-2023-45282HIGH7.5In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.
CVE-2023-21266HIGH7.8In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a ...
CVE-2023-32972HIGH7.2A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2023-32971HIGH7.2A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2023-44243HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Dylan Blokhuis Instant CSS plugin <= 1.2.1 versions.
CVE-2023-44233HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in FooPlugins Best WordPress Gallery Plugin – FooGallery plugin <= 2.2.4...
CVE-2023-39928HIGH8.8A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page ...
CVE-2023-44146HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Checkfront Inc. Checkfront Online Booking System plugin <= 3.6 versio...
CVE-2023-41950HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Laposta - Roel Bousardt Laposta Signup Basic plugin <= 1.4.1 versions...
CVE-2023-41801HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugi...
CVE-2023-41732HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Blocks plugin <= 1.0.20 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now