2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-47105HIGH8.6exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd p...
CVE-2023-49203HIGH7.5Technitium 11.5.3 allows remote attackers to cause a denial of service (bandwidth amplification) because the DNSBomb man...
CVE-2023-28457HIGH7.5An issue was discovered in Technitium through 11.0.3. It enables attackers to conduct a DNS cache poisoning attack and i...
CVE-2023-28456HIGH7.5An issue was discovered in Technitium through 11.0.2. It enables attackers to launch amplification attacks (3 times more...
CVE-2023-28455HIGH7.5An issue was discovered in Technitium through 11.0.2. The forwarding mode enables attackers to create a query loop using...
CVE-2023-28452HIGH7.5An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a ...
CVE-2023-28451HIGH7.5An issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which ...
CVE-2023-45854HIGH7.5A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shoppin...
CVE-2023-43626HIGH8.7Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable ...
CVE-2023-42772HIGH8.7Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to pot...
CVE-2023-41833HIGH8.7A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalat...
CVE-2023-6841HIGH7.5A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an atta...
CVE-2023-37233HIGH8.8Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
CVE-2023-37232HIGH7.5Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.
CVE-2023-37230HIGH8.8Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.
CVE-2023-37229HIGH8.8Loftware Spectrum before 5.1 allows SSRF.
CVE-2023-30756HIGH8.2A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP...
CVE-2023-28827HIGH8.2A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP...
CVE-2023-46809HIGH7.4Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL whi...
CVE-2023-30587HIGH7.5A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using ...
CVE-2023-30584HIGH7.7A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This f...
CVE-2023-30583HIGH7.5fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--all...
CVE-2023-51367HIGH8.8A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2023-50360HIGH8.8A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow aut...
CVE-2023-47563HIGH8.8An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now