2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-4033HIGH7.8OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.
CVE-2023-37772HIGH8.8Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /...
CVE-2023-3825HIGH7.5 PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads...
CVE-2023-3983HIGH8.8An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authentic...
CVE-2023-4004HIGH7.8A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove functio...
CVE-2023-3997HIGH7.8Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s t...
CVE-2023-38750HIGH7.5In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and ...
CVE-2023-33534HIGH8.8A Cross-Site Request Forgery (CSRF) in Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G software version S10G_3.11....
CVE-2023-34359HIGH7.5ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted req...
CVE-2023-34358HIGH7.5ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted req...
CVE-2023-35019HIGH8.8IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary c...
CVE-2023-37219HIGH7.8 Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File
CVE-2023-37218HIGH7.5 Tadiran Telecom Aeonix - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-32225HIGH7.2 Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -  A malicious user with administrative privileges m...
CVE-2023-36542HIGH8.8Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retriev...
CVE-2023-2313HIGH8.8Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who...
CVE-2023-3598HIGH8.8Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially e...
CVE-2023-38684HIGH7.5Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o...
CVE-2023-31937HIGH7.2Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31936HIGH7.2Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31933HIGH7.2Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-31932HIGH7.2Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary cod...
CVE-2023-3670HIGH7.3In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions ...
CVE-2023-38609HIGH7.5An injection issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.5. An app may b...
CVE-2023-38601HIGH7.5This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey 12...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now