2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-40957 | HIGH | 8.8 | 1.1% | Sep 15, 2023 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fix... |
| CVE-2023-40956 | HIGH | 8.8 | 1.0% | Sep 15, 2023 | A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute ... |
| CVE-2023-40955 | HIGH | 8.8 | 1.1% | Sep 15, 2023 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fix... |
| CVE-2023-38891 | HIGH | 8.8 | 0.9% | Sep 14, 2023 | SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the ... |
| CVE-2023-40868 | HIGH | 8.8 | 1.2% | Sep 14, 2023 | Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbi... |
| CVE-2023-25584 | HIGH | 7.1 | 0.4% | Sep 14, 2023 | An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils. |
| CVE-2023-32643 | HIGH | 7.8 | 0.4% | Sep 14, 2023 | A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fi... |
| CVE-2023-32636 | HIGH | 7.5 | 0.8% | Sep 14, 2023 | A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by add... |
| CVE-2023-29499 | HIGH | 7.5 | 0.8% | Sep 14, 2023 | A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, lea... |
| CVE-2023-36250 | HIGH | 7.8 | 0.6% | Sep 14, 2023 | CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via cr... |
| CVE-2023-42180 | HIGH | 8.8 | 0.6% | Sep 14, 2023 | An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute htm... |
| CVE-2023-1108 | HIGH | 7.5 | 1.8% | Sep 14, 2023 | A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake sta... |
| CVE-2023-2848 | HIGH | 8.8 | 0.3% | Sep 14, 2023 | Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a miss... |
| CVE-2023-38557 | HIGH | 7.8 | 0.1% | Sep 14, 2023 | A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper ac... |
| CVE-2023-4516 | HIGH | 7.8 | 0.2% | Sep 14, 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allo... |
| CVE-2023-41267 | HIGH | 7.8 | 0.5% | Sep 14, 2023 | In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect... |
| CVE-2023-38205 | HIGH | 7.5 | 99.7% | Sep 14, 2023 | Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improp... |
| CVE-2023-4814 | HIGH | 7.1 | 0.1% | Sep 14, 2023 | A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete a... |
| CVE-2023-23845 | HIGH | 7.2 | 5.4% | Sep 13, 2023 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ... |
| CVE-2023-23840 | HIGH | 7.2 | 5.4% | Sep 13, 2023 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ... |
| CVE-2023-40850 | HIGH | 7.5 | 0.7% | Sep 13, 2023 | netentsec NS-ASG 6.3 is vulnerable to Incorrect Access Control. There is a file leak in the website source code of the a... |
| CVE-2023-4785 | HIGH | 7.5 | 0.7% | Sep 13, 2023 | Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux... |
| CVE-2023-2680 | HIGH | 8.2 | 0.2% | Sep 13, 2023 | This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for ... |
| CVE-2023-20236 | HIGH | 7.8 | 0.1% | Sep 13, 2023 | A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to insta... |
| CVE-2023-20191 | HIGH | 7.5 | 0.5% | Sep 13, 2023 | A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now