2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-41744HIGH7.8Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acron...
CVE-2023-41743HIGH7.8Local privilege escalation due to insecure driver communication port permissions. The following products are affected: A...
CVE-2023-34392HIGH8.8 A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Gr...
CVE-2023-31173HIGH8.4Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Win...
CVE-2023-31172HIGH7.4 An Incomplete Filtering of Special Elements vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerat...
CVE-2023-31167HIGH8.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Schweitzer Engineering L...
CVE-2023-41742HIGH7.5Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agen...
CVE-2023-41640HIGH8.8An improper error handling vulnerability in the component ErroreNonGestito.aspx of GruppoSCAI RealGimm 1.1.37p38 allows ...
CVE-2023-41638HIGH8.8An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attack...
CVE-2023-33835HIGH7.5IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information th...
CVE-2023-41741HIGH7.5Exposure of sensitive information to an unauthorized actor vulnerability in cgi component in Synology Router Manager (SR...
CVE-2023-41738HIGH8.8Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Do...
CVE-2023-20900HIGH7.5A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vspher...
CVE-2023-3677HIGH8.8The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in vers...
CVE-2023-3636HIGH8.8The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6....
CVE-2023-2229HIGH8.8The Quick Post Duplicator for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, an...
CVE-2023-3489HIGH7.5The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in t...
CVE-2023-39139HIGH7.8An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
CVE-2023-39138HIGH7.8An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.
CVE-2023-39137HIGH7.8An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
CVE-2023-39135HIGH7.8An issue in Zip Swift v2.1.2 allows attackers to execute a path traversal attack via a crafted zip entry.
CVE-2023-41039HIGH7.7RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality...
CVE-2023-4640HIGH7.5The controller responsible for setting the logging level does not include any authorization checks to ensure the user is...
CVE-2023-4571HIGH8.6In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject Am...
CVE-2023-40598HIGH8.8In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a leg...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now