2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-42456HIGH8.1Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo att...
CVE-2023-42457HIGH7.5plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and ...
CVE-2023-43637HIGH7.8 Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the las...
CVE-2023-43634HIGH8.8 When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous proje...
CVE-2023-43633HIGH8.8 On boot, the Pillar eve container checks for the existence and content of “/config/GlobalConfig/global.json”. If the f...
CVE-2023-43631HIGH8.8 On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is pr...
CVE-2023-43274HIGH7.5Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter.
CVE-2023-4152HIGH7.5Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a path traversal ...
CVE-2023-43669HIGH7.5The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consum...
CVE-2023-37279HIGH7.5Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can s...
CVE-2023-42321HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary co...
CVE-2023-39677HIGH7.5MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInf...
CVE-2023-43138HIGH8.8TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT ru...
CVE-2023-43137HIGH8.8TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rul...
CVE-2023-42335HIGH8.8Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to exec...
CVE-2023-42331HIGH8.8A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads....
CVE-2023-42147HIGH7.5An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component.
CVE-2023-41484HIGH8.1An issue in cimg.eu Cimg Library v2.9.3 allows an attacker to obtain sensitive information via a crafted JPEG file.
CVE-2023-37410HIGH7.8IBM Personal Communications 14.05, 14.06, and 15.0.0 could allow a local user to escalate their privileges to the SYSTEM...
CVE-2023-43500HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows atta...
CVE-2023-43498HIGH8.1In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates tem...
CVE-2023-43497HIGH8.1In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates t...
CVE-2023-43496HIGH8.8Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the d...
CVE-2023-42660HIGH8.8 In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 ...
CVE-2023-40043HIGH7.2 In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now