2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-36618HIGH8.8Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-...
CVE-2023-44209HIGH7.8Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec...
CVE-2023-42809HIGH8.8Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received fr...
CVE-2023-42449HIGH8.1Hydra is the two-layer scalability solution for Cardano. Prior to version 0.13.0, it is possible for a malicious head in...
CVE-2023-42824HIGH7.8The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may ...
CVE-2023-42448HIGH8.1Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the cont...
CVE-2023-39191HIGH8.2An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of...
CVE-2023-43804HIGH8.1urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or pro...
CVE-2023-20259HIGH7.5A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, rem...
CVE-2023-20235HIGH8.8A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastr...
CVE-2023-43838HIGH7.8An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code ...
CVE-2023-4237HIGH7.8A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the priv...
CVE-2023-40559HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Dynamic Pricing and Discount Rules for WooCommerce plugin...
CVE-2023-3665HIGH7.8 A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable th...
CVE-2023-40561HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Enhanced Ecommerce Google Analytics for WooCommerce plugi...
CVE-2023-27433HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative allows Cross Site Request Forgery...
CVE-2023-25025HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 ...
CVE-2023-1832HIGH8.1An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant...
CVE-2023-43261HIGH7.5An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensiti...
CVE-2023-3361HIGH7.5A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as...
CVE-2023-3038HIGH7.5SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote atta...
CVE-2023-3037HIGH8.6Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a re...
CVE-2023-22618HIGH7.8If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users ...
CVE-2023-4997HIGH8.8Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to cha...
CVE-2023-4586HIGH7.4A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostna...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now