2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-39912MEDIUM4.9Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine wh...
CVE-2023-4688MEDIUM5.5Sensitive information leak through log files. The following products are affected: Acronis Agent (Linux, macOS, Windows)...
CVE-2023-41751MEDIUM5.5Sensitive information disclosure due to improper token expiration validation. The following products are affected: Acron...
CVE-2023-41750MEDIUM5.5Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux...
CVE-2023-41747MEDIUM6.5Sensitive information disclosure due to unauthenticated path traversal. The following products are affected: Acronis Clo...
CVE-2023-41745MEDIUM5.5Sensitive information disclosure due to excessive collection of system information. The following products are affected:...
CVE-2023-41045MEDIUM5.3Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Gr...
CVE-2023-4683MEDIUM5.5NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2023-4682MEDIUM5.5Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2023-4681MEDIUM5.5NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2023-4678MEDIUM5.5Divide By Zero in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2023-41717MEDIUM5.5Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file downl...
CVE-2023-34391MEDIUM5.5Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software o...
CVE-2023-31174MEDIUM6.5 A Cross-Site Request Forgery (CSRF) vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configur...
CVE-2023-31171MEDIUM6.5 An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in the Schweitzer...
CVE-2023-31170MEDIUM6.5 An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SE...
CVE-2023-31169MEDIUM5.7 An Improper Handling of Unicode Encoding vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator ...
CVE-2023-31168MEDIUM6.5 An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer Engineering Laboratories SE...
CVE-2023-41642MEDIUM6.1Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealG...
CVE-2023-41635MEDIUM6.5A XML External Entity (XXE) vulnerability in the VerifichePeriodiche.aspx component of GruppoSCAI RealGimm v1.1.37p38 al...
CVE-2023-33834MEDIUM5.3IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information th...
CVE-2023-41740MEDIUM5.3Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synolog...
CVE-2023-41739MEDIUM6.5Uncontrolled resource consumption vulnerability in File Functionality in Synology Router Manager (SRM) before 1.3.1-9346...
CVE-2023-4500MEDIUM4.8The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter ...
CVE-2023-4471MEDIUM6.1The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_d...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now