2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-45698MEDIUM6.1Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropria...
CVE-2023-45696HIGH7.5Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allow...
CVE-2023-28077MEDIUM4.4 Dell BSAFE SSL-J, versions prior to 6.5, and versions 7.0 and 7.1 contain a debug message revealing unnecessary informa...
CVE-2023-6935MEDIUM5.9wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher styl...
CVE-2023-45718HIGH7.5Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persi...
CVE-2023-45716MEDIUM4.1Sametime is impacted by sensitive information passed in URL.
CVE-2023-50349HIGH8.8Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy applica...
CVE-2023-50386HIGH8.8Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Fu...
CVE-2023-50298HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: ...
CVE-2023-50292HIGH7.5Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerabil...
CVE-2023-50291HIGH7.5Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8...
CVE-2023-6677CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Te...
CVE-2023-6724HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Lim...
CVE-2023-6716Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. All references and descriptions in this record have been remov...
CVE-2023-50026CRITICAL9.8SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop vers...
CVE-2023-46350CRITICAL9.8SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for...
CVE-2023-39683MEDIUM6.1Cross Site Scripting (XSS) vulnerability in EasyEmail v.4.12.2 and before allows a local attacker to execute arbitrary c...
CVE-2023-31506MEDIUM5.4A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to ...
CVE-2023-51761HIGH8.1In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass a...
CVE-2023-49716CRITICAL9.8 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbit...
CVE-2023-46687CRITICAL9.8 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execu...
CVE-2023-43609CRITICAL9.1In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain a...
CVE-2023-45191HIGH7.5IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a rem...
CVE-2023-45190MEDIUM6.1IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper valida...
CVE-2023-45187HIGH8.8IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now