2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-5269HIGH8.8A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as critical. Affe...
CVE-2023-5268HIGH7.2A vulnerability was found in DedeBIZ 6.2 and classified as critical. This issue affects some unknown processing of the f...
CVE-2023-5266HIGH8.8A vulnerability, which was classified as critical, was found in DedeBIZ 6.2. This affects an unknown part of the file /s...
CVE-2023-5264HIGH7.2A vulnerability classified as critical was found in huakecms 3.0. Affected by this vulnerability is an unknown functiona...
CVE-2023-5289HIGH8.8Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.
CVE-2023-5263HIGH8.8A vulnerability was found in ZZZCMS 2.1.7 and classified as critical. Affected by this issue is the function restore of ...
CVE-2023-5262HIGH8.8A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. Affected by this vulnerability is...
CVE-2023-3413HIGH7.5An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting fr...
CVE-2023-3922HIGH7.1An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting fr...
CVE-2023-32477HIGH7.8 Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-...
CVE-2023-3917HIGH7.5Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16....
CVE-2023-44466HIGH8.8An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness erro...
CVE-2023-30591HIGH7.5Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.sta...
CVE-2023-44464HIGH7.8pretix before 2023.7.2 allows Pillow to parse EPS files.
CVE-2023-5077HIGH7.5The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditio...
CVE-2023-43662HIGH8.6ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endp...
CVE-2023-43014HIGH8.8Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'la...
CVE-2023-5185HIGH8.8Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of p...
CVE-2023-4316HIGH7.5Zod in versions 3.21.0 up to and including 3.22.3 allows an attacker to perform a denial of service while validating ema...
CVE-2023-43740HIGH8.8Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_...
CVE-2023-43226HIGH8.8An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute ...
CVE-2023-5256HIGH7.5In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause se...
CVE-2023-43044HIGH7.5IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send ...
CVE-2023-40375HIGH7.8Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A m...
CVE-2023-5217HIGH8.8Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remo...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now