2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-40957HIGH8.8A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fix...
CVE-2023-40956HIGH8.8A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute ...
CVE-2023-40955HIGH8.8A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fix...
CVE-2023-38891HIGH8.8SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the ...
CVE-2023-40868HIGH8.8Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbi...
CVE-2023-25584HIGH7.1An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
CVE-2023-32643HIGH7.8A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fi...
CVE-2023-32636HIGH7.5A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by add...
CVE-2023-29499HIGH7.5A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, lea...
CVE-2023-36250HIGH7.8CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via cr...
CVE-2023-42180HIGH8.8An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute htm...
CVE-2023-1108HIGH7.5A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake sta...
CVE-2023-2848HIGH8.8Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a miss...
CVE-2023-38557HIGH7.8A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper ac...
CVE-2023-4516HIGH7.8 A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allo...
CVE-2023-41267HIGH7.8In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect...
CVE-2023-38205HIGH7.5Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improp...
CVE-2023-4814HIGH7.1 A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete a...
CVE-2023-23845HIGH7.2The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ...
CVE-2023-23840HIGH7.2The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with ...
CVE-2023-40850HIGH7.5netentsec NS-ASG 6.3 is vulnerable to Incorrect Access Control. There is a file leak in the website source code of the a...
CVE-2023-4785HIGH7.5Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux...
CVE-2023-2680HIGH8.2This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for ...
CVE-2023-20236HIGH7.8A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to insta...
CVE-2023-20191HIGH7.5A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now