2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-1386HIGH7.8A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes a...
CVE-2023-3417HIGH7.5Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly...
CVE-2023-2761HIGH7.2The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter befo...
CVE-2023-38060HIGH8.8Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate ope...
CVE-2023-38056HIGH7.2Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule us...
CVE-2023-3852HIGH7.2A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been declared as critical. This vulnerability affect...
CVE-2023-28133HIGH7.8Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration fi...
CVE-2023-3842HIGH7.8A vulnerability was found in Pointware EasyInventory 1.0.12.0 and classified as critical. This issue affects some unknow...
CVE-2023-3841HIGH8.8A vulnerability has been found in NxFilter 4.3.2.5 and classified as problematic. This vulnerability affects unknown cod...
CVE-2023-3839HIGH7.2A vulnerability, which was classified as problematic, has been found in DedeBIZ 6.2.10. Affected by this issue is some u...
CVE-2023-3776HIGH7.8A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privi...
CVE-2023-3611HIGH7.8An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve loca...
CVE-2023-3610HIGH7.8A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr...
CVE-2023-3609HIGH7.8A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local priv...
CVE-2023-37918HIGH7.5Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. A vulnerability h...
CVE-2023-37917HIGH8.8KubePi is an opensource kubernetes management panel. A normal user has permission to create/update users, they can becom...
CVE-2023-37916HIGH7.5KubePi is an opensource kubernetes management panel. The endpoint /kubepi/api/v1/users/search?pageNum=1&&pageSize=10 lea...
CVE-2023-37915HIGH7.5OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenD...
CVE-2023-35077HIGH7.5An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update t...
CVE-2023-36339HIGH7.5An access control issue in WebBoss.io CMS v3.7.0.1 allows attackers to access the Website Backup Tool via a crafted GET ...
CVE-2023-3820HIGH7.2 SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4.
CVE-2023-35086HIGH7.2 It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly...
CVE-2023-28730HIGH7.8A memory corruption vulnerability Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbit...
CVE-2023-28729HIGH7.8A type confusion vulnerability in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbit...
CVE-2023-28728HIGH7.8A stack-based buffer overflow in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitr...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now