2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-39125 | HIGH | 7.5 | 0.6% | Aug 18, 2023 | NTSC-CRT 2.2.1 has an integer overflow and out-of-bounds write in loadBMP in bmp_rw.c because a file's width, height, an... |
| CVE-2023-40171 | HIGH | 7.5 | 0.8% | Aug 17, 2023 | Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for s... |
| CVE-2023-40315 | HIGH | 8 | 2.5% | Aug 17, 2023 | In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FIL... |
| CVE-2023-36106 | HIGH | 7.5 | 0.7% | Aug 17, 2023 | An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive info... |
| CVE-2023-31946 | HIGH | 7.2 | 1.2% | Aug 17, 2023 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code ... |
| CVE-2023-31945 | HIGH | 7.2 | 1.1% | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-31944 | HIGH | 7.2 | 1.1% | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-31943 | HIGH | 7.2 | 1.1% | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-31941 | HIGH | 7.2 | 1.2% | Aug 17, 2023 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code ... |
| CVE-2023-31940 | HIGH | 7.2 | 1.1% | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-31939 | HIGH | 7.2 | 1.1% | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-31938 | HIGH | 7.2 | 1.1% | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod... |
| CVE-2023-40313 | HIGH | 8.8 | 0.7% | Aug 17, 2023 | A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridi... |
| CVE-2023-38843 | HIGH | 8 | 0.7% | Aug 17, 2023 | An issue in Atlos v.1.0 allows an authenticated attacker to execute arbitrary code via a crafted payload into the descri... |
| CVE-2023-40165 | HIGH | 7.5 | 0.4% | Aug 17, 2023 | rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malici... |
| CVE-2023-37914 | HIGH | 8.8 | 1.5% | Aug 17, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who ca... |
| CVE-2023-4030 | HIGH | 7.8 | 0.2% | Aug 17, 2023 | A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the ... |
| CVE-2023-3078 | HIGH | 7.8 | 0.2% | Aug 17, 2023 | An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an a... |
| CVE-2023-2914 | HIGH | 7.5 | 27.0% | Aug 17, 2023 | The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer ove... |
| CVE-2023-40272 | HIGH | 7.5 | 1.7% | Aug 17, 2023 | Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in ... |
| CVE-2023-38902 | HIGH | 8.8 | 2.2% | Aug 17, 2023 | A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 ser... |
| CVE-2023-38838 | HIGH | 7.5 | 0.7% | Aug 17, 2023 | SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via the e... |
| CVE-2023-3698 | HIGH | 8.1 | 0.5% | Aug 17, 2023 | Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the inte... |
| CVE-2023-3697 | HIGH | 8.8 | 0.5% | Aug 17, 2023 | Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the inte... |
| CVE-2023-2910 | HIGH | 8.8 | 1.3% | Aug 17, 2023 | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service fun... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now