2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-44155HIGH7.5Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Wind...
CVE-2023-44154HIGH8.1Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Ac...
CVE-2023-44153HIGH7.5Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are...
CVE-2023-44125HIGH7.8The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft...
CVE-2023-44123HIGH7.8The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/...
CVE-2023-44122HIGH7.8The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreenset...
CVE-2023-44044HIGH7.2Super Store Finder v3.6 and below was discovered to contain a SQL injection vulnerability via the Search parameter at /a...
CVE-2023-43856HIGH7.5Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateContr...
CVE-2023-43825HIGH7.8Relative path traversal vulnerability in Shihonkanri Plus Ver9.0.3 and earlier allows a local attacker to execute an arb...
CVE-2023-43646HIGH7.5get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versio...
CVE-2023-43610HIGH8.8SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with edit...
CVE-2023-43381HIGH7.5SQL Injection vulnerability in Tianchoy Blog v.1.8.8 allows a remote attacker to obtain sensitive information via the id...
CVE-2023-42820HIGH8.2JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, pote...
CVE-2023-42819HIGH8.8JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system....
CVE-2023-42487HIGH7.5Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-42486HIGH7.8Fortect - CWE-428: Unquoted Search Path or Element, may be used by local user to elevate privileges.
CVE-2023-42460HIGH7.5Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is...
CVE-2023-41995HIGH7.8A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS...
CVE-2023-41984HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and ...
CVE-2023-41333HIGH8.1Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability ...
CVE-2023-41326HIGH8.8GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide...
CVE-2023-41324HIGH8.8GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide...
CVE-2023-41322HIGH8.8GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide...
CVE-2023-41309HIGH7.5Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability ma...
CVE-2023-41308HIGH7.5Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now