2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-32186HIGH7.5A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s s...
CVE-2023-32184HIGH7.8A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute...
CVE-2023-41443HIGH7.2SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted scrip...
CVE-2023-42443HIGH8.1Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In version 0.3.9 and prior, under ce...
CVE-2023-39452HIGH7.5 The web application that owns the device clearly stores the credentials within the user management sectio...
CVE-2023-39446HIGH8.8 Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the ...
CVE-2023-41965HIGH7.5Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack ...
CVE-2023-40221HIGH8.8 The absence of filters when loading some sections in the web application of the vulnerable device allows po...
CVE-2023-42328HIGH8.8An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and ex...
CVE-2023-41595HIGH7.5An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
CVE-2023-42387HIGH7.5An issue in TDSQL Chitu management platform v.10.3.19.5.0 allows a remote attacker to obtain sensitive information via g...
CVE-2023-34195HIGH7.8An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The imple...
CVE-2023-32187HIGH7.5An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s se...
CVE-2023-41929HIGH7.3A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a...
CVE-2023-34999HIGH7.2A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) tha...
CVE-2023-43115HIGH8.8In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript d...
CVE-2023-42525HIGH7.5Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSec...
CVE-2023-42524HIGH7.5Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSec...
CVE-2023-42523HIGH7.5Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecur...
CVE-2023-42522HIGH7.5Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. T...
CVE-2023-42521HIGH7.5Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects ...
CVE-2023-5036HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.
CVE-2023-42526HIGH7.5Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affe...
CVE-2023-42520HIGH7.5Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects ...
CVE-2023-5033HIGH7.2A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the f...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now