2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-3421HIGH8.8Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap c...
CVE-2023-3420HIGH8.8Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corr...
CVE-2023-34924HIGH7.5H3C Magic B1STW B1STV100R012 was discovered to contain a stack overflow via the function SetAPInfoById. This vulnerabili...
CVE-2023-34463HIGH8.1DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In af...
CVE-2023-3113HIGH7.5An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) ser...
CVE-2023-35933HIGH7.5OPenFGA is an open source authorization/permission engine built for developers. OpenFGA versions v1.1.0 and prior are vu...
CVE-2023-34420HIGH7.2A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted call...
CVE-2023-34418HIGH8.1A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to ...
CVE-2023-2992HIGH7.5An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which ca...
CVE-2023-36252HIGH8.8An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code a...
CVE-2023-2005HIGH8.8Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugi...
CVE-2023-36301HIGH7.5Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.
CVE-2023-25307HIGH7.8nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal.
CVE-2023-25306HIGH7.5MultiMC Launcher <= 0.6.16 is vulnerable to Directory Traversal.
CVE-2023-36631HIGH7.8Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged us...
CVE-2023-3398HIGH7.5Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.
CVE-2023-1150HIGH7.5Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS...
CVE-2023-36664HIGH7.8Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | p...
CVE-2023-36661HIGH7.5Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyIn...
CVE-2023-36663HIGH8.8it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the so...
CVE-2023-36632HIGH7.5The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum ...
CVE-2023-36630HIGH8.8In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.
CVE-2023-36612HIGH7.5Directory traversal can occur in the Basecamp com.basecamp.bc3 application before 4.2.1 for Android, which may allow an ...
CVE-2023-1722HIGH8.8Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible b...
CVE-2023-1721HIGH7.2Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible b...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now