2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-50344MEDIUM5.4HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthent...
CVE-2023-50343MEDIUM6.5HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints a...
CVE-2023-50342MEDIUM4.3HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability.  A user can obtain certai...
CVE-2023-50341HIGH7.5HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated a...
CVE-2023-45724CRITICAL9.8HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the ...
CVE-2023-45723CRITICAL9.8HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoint...
CVE-2023-45722CRITICAL9.8HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to ...
CVE-2023-50351CRITICAL9.1HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compro...
CVE-2023-50350HIGH7.5HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an a...
CVE-2023-50348MEDIUM5.3HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error me...
CVE-2023-50346MEDIUM4.3HCL DRYiCE MyXalytics is impacted by an information disclosure vulnerability. Certain endpoints within the application d...
CVE-2023-50345MEDIUM6.1HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to m...
CVE-2023-41783HIGH7.8There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the  program  failed to adequately validate the...
CVE-2023-41780HIGH7.8There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the  program  failed to adequately validate the...
CVE-2023-41779MEDIUM5.5There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an ...
CVE-2023-41776HIGH7.8There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can cre...
CVE-2023-49558MEDIUM5.5An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params functio...
CVE-2023-49557MEDIUM5.5An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first fun...
CVE-2023-49556MEDIUM5.5Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_...
CVE-2023-49555MEDIUM5.5An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in ...
CVE-2023-49554MEDIUM5.5Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_dir...
CVE-2023-49553HIGH7.5An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the...
CVE-2023-49552HIGH7.5An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_s...
CVE-2023-49551HIGH7.5An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function ...
CVE-2023-49550HIGH7.5An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now