2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-3701HIGH8.8Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerabili...
CVE-2023-3512HIGH7.5Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploit...
CVE-2023-37995HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 ...
CVE-2023-2422HIGH7.1A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does ...
CVE-2023-25980HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in CAGE Web Design | Rolf van Gelder Optimize Database after Deleting Re...
CVE-2023-25788HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Saphali Saphali Woocommerce Lite plugin <= 1.8.13 versions.
CVE-2023-25489HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Update Theme and Plugins from Zip File plugin <= 2.0.0 ver...
CVE-2023-1584HIGH7.5A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an inse...
CVE-2023-5377HIGH7.1Out-of-bounds Read in GitHub repository gpac/gpac prior to v2.2.2-DEV.
CVE-2023-5369HIGH7.1Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE capabilities on the input...
CVE-2023-30738HIGH7.8An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro,...
CVE-2023-30733HIGH7.8Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attac...
CVE-2023-30727HIGH7.5Improper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi an...
CVE-2023-30692HIGH7.8Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch pr...
CVE-2023-30690HIGH7.8Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileg...
CVE-2023-43176HIGH8.8A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplyi...
CVE-2023-43976HIGH8.1An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race conditio...
CVE-2023-5255HIGH7.5For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates fro...
CVE-2023-4911HIGH7.8A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environ...
CVE-2023-4817HIGH8.8This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the uploa...
CVE-2023-4884HIGH7.5An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to t...
CVE-2023-4883HIGH7.5 Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the corr...
CVE-2023-4882HIGH7.5DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could...
CVE-2023-4929HIGH8.8All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. ...
CVE-2023-41693HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview MyCryptoCheckout plugin <= 2.125 versions.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now