2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-37261HIGH8.8OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. This issue affects every versi...
CVE-2023-36992HIGH7.2PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP ...
CVE-2023-36201HIGH7.5An issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted scri...
CVE-2023-33664HIGH8.8ai-dev aicombinationsonfly before v0.3.1 was discovered to contain a SQL injection vulnerability via the component /incl...
CVE-2023-25201HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in MultiTech Conduit AP MTCAP2-L4E1 MTCAP2-L4E1-868-042A v.6.0.0 allows ...
CVE-2023-3534HIGH7.5A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unk...
CVE-2023-32183HIGH7.8Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hac...
CVE-2023-37192HIGH7.5Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within...
CVE-2023-35120HIGH8.8 PiiGAB M-Bus is vulnerable to cross-site request forgery. An attacker who wants to execute a certain command could send...
CVE-2023-31277HIGH7.5 PiiGAB M-Bus transmits credentials in plaintext format.
CVE-2023-20899HIGH7.5VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagno...
CVE-2023-35934HIGH8.2yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external down...
CVE-2023-30195HIGH7.5In the module "Detailed Order" (lgdetailedorder) in version up to 1.1.20 from Linea Grafica for PrestaShop, a guest can ...
CVE-2023-3529HIGH7.5A vulnerability classified as problematic has been found in Rotem Dynamics Rotem CRM up to 20230729. This affects an unk...
CVE-2023-36461HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Masto...
CVE-2023-36456HIGH7.3authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the so...
CVE-2023-37260HIGH7.5league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2...
CVE-2023-36830HIGH7.8SQLFluff is a SQL linter. Prior to version 2.1.2, in environments where untrusted users have access to the config files,...
CVE-2023-34193HIGH8.8File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obt...
CVE-2023-36969HIGH8.8CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
CVE-2023-30325HIGH7.5SQL Injection vulnerability in textMessage parameter in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine v.1.0, all...
CVE-2023-30323HIGH7.5SQL Injection vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0, allows atta...
CVE-2023-25583HIGH7.2Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A spec...
CVE-2023-25582HIGH7.2Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A spec...
CVE-2023-25124HIGH7.2Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of a...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now