2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-37225MEDIUM6.1Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links.
CVE-2023-31455HIGH7.5Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.
CVE-2023-31289HIGH7.5Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.
CVE-2023-51771CRITICAL9.8In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer o...
CVE-2023-30451MEDIUM4.9In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary...
CVE-2023-7100CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected...
CVE-2023-7099CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1....
CVE-2023-49880HIGH7.5In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending...
CVE-2023-43064HIGH7.8Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqual...
CVE-2023-7098MEDIUM5.3** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in icret EasyImages 2.8.3. This vuln...
CVE-2023-7097CRITICAL9.8A vulnerability classified as critical has been found in code-projects Water Billing System 1.0. This affects an unknown...
CVE-2023-7096CRITICAL9.8A flaw has been found in code-projects Faculty Management System 1.0. The affected element is an unknown function of the...
CVE-2023-7095CRITICAL9.8A vulnerability, which was classified as critical, has been found in Totolink A7100RU 7.4cu.2313_B20191024. Affected by ...
CVE-2023-7094HIGH7.5A vulnerability classified as problematic was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected by th...
CVE-2023-7093HIGH7.8A vulnerability classified as critical has been found in KylinSoft kylin-system-updater up to 2.0.5.16-0k2.33. Affected ...
CVE-2023-7092MEDIUM4.3A vulnerability was found in Uniway UW-302VP 2.0. It has been rated as problematic. This issue affects some unknown proc...
CVE-2023-7102CRITICAL9.8Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed P...
CVE-2023-7101HIGH7.8Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerabl...
CVE-2023-7091HIGH8.8A vulnerability was found in Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown ...
CVE-2023-51714CRITICAL9.8An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before ...
CVE-2023-51767HIGH7OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) bec...
CVE-2023-51766MEDIUM5.3Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a publi...
CVE-2023-51765MEDIUM5.3sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitati...
CVE-2023-51764MEDIUM5.3Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and ...
CVE-2023-51763CRITICAL9.8csv_builder.rb in ActiveAdmin (aka Active Admin) before 3.2.0 allows CSV injection.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now