2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-49117MEDIUM5.4PowerCMS (6 Series, 5 Series, and 4 Series) contains a stored cross-site scripting vulnerability. If this vulnerability ...
CVE-2023-28616HIGH7.5An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x...
CVE-2023-27150MEDIUM5.4openCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of ...
CVE-2023-7111CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. Affected is...
CVE-2023-38321HIGH7.5OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial...
CVE-2023-49954CRITICAL9.8The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search stri...
CVE-2023-49944MEDIUM6.7The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local adm...
CVE-2023-49226HIGH7.2An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administ...
CVE-2023-48652MEDIUM4.3Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via /ccm/system/dialogs/logs/delete_all/s...
CVE-2023-38826MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in Follet Learning Solutions Destiny through 20.0_1U. via the handlewp...
CVE-2023-36486HIGH7.2The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system comm...
CVE-2023-36485HIGH7.2The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system comm...
CVE-2023-31224CRITICAL9.8There is broken access control during authentication in Jamf Pro Server before 10.46.1.
CVE-2023-47247MEDIUM4.3In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base artic...
CVE-2023-47091HIGH7.5An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through...
CVE-2023-37188HIGH7.5C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_rate_decompress at zfp/b...
CVE-2023-37187HIGH7.5C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the zfp/blosc2-zfp.c zfp_acc_decompress. ...
CVE-2023-37186HIGH7.5C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference in ndlz/ndlz8x8.c via a NULL pointer to memse...
CVE-2023-37185HIGH7.5C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_prec_decompress at zfp/b...
CVE-2023-31297MEDIUM4.8An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Na...
CVE-2023-28872HIGH8.8Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privile...
CVE-2023-51772HIGH8.8One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Direct...
CVE-2023-49328HIGH7.2On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated syst...
CVE-2023-48654CRITICAL9.8One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Direct...
CVE-2023-40236MEDIUM5.3In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, whic...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now