2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-39125HIGH7.5NTSC-CRT 2.2.1 has an integer overflow and out-of-bounds write in loadBMP in bmp_rw.c because a file's width, height, an...
CVE-2023-40171HIGH7.5Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for s...
CVE-2023-40315HIGH8In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FIL...
CVE-2023-36106HIGH7.5An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive info...
CVE-2023-31946HIGH7.2File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code ...
CVE-2023-31945HIGH7.2SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31944HIGH7.2SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31943HIGH7.2SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31941HIGH7.2File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code ...
CVE-2023-31940HIGH7.2SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31939HIGH7.2SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31938HIGH7.2SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-40313HIGH8.8A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridi...
CVE-2023-38843HIGH8An issue in Atlos v.1.0 allows an authenticated attacker to execute arbitrary code via a crafted payload into the descri...
CVE-2023-40165HIGH7.5rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malici...
CVE-2023-37914HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who ca...
CVE-2023-4030HIGH7.8A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the ...
CVE-2023-3078HIGH7.8An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an a...
CVE-2023-2914HIGH7.5The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer ove...
CVE-2023-40272HIGH7.5Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in ...
CVE-2023-38902HIGH8.8A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 ser...
CVE-2023-38838HIGH7.5SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via the e...
CVE-2023-3698HIGH8.1Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the inte...
CVE-2023-3697HIGH8.8Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the inte...
CVE-2023-2910HIGH8.8Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service fun...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now