2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-38513MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom)....
CVE-2023-37871HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: ...
CVE-2023-6562HIGH7.5JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachab...
CVE-2023-6912CRITICAL9.8Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authe...
CVE-2023-6910MEDIUM6.5A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticat...
CVE-2023-6769MEDIUM4.6Stored XSS vulnerability in Amazing Little Poll, affecting versions 1.3 and 1.4. This vulnerability allows a remote atta...
CVE-2023-6768CRITICAL9.8Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allo...
CVE-2023-50628CRITICAL9.8Buffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive ...
CVE-2023-50044CRITICAL9.8Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an i...
CVE-2023-37544HIGH7.5Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong en...
CVE-2023-0011MEDIUM6.8A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system commands using specificall...
CVE-2023-6977HIGH7.5This vulnerability enables malicious users to read sensitive files on the server.
CVE-2023-6976HIGH8.8This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the contex...
CVE-2023-6975CRITICAL9.8A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models...
CVE-2023-6974CRITICAL9.8A malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it cou...
CVE-2023-47707MEDIUM5.4IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2023-47705MEDIUM4.3IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to imp...
CVE-2023-47703MEDIUM5.3IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a det...
CVE-2023-47702CRITICAL9.1IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An ...
CVE-2023-47706HIGH8.8IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file ty...
CVE-2023-47704HIGH7.5IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source co...
CVE-2023-27172CRITICAL9.1Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the ...
CVE-2023-6689HIGH8.8 A successful CSRF attack could force the user to perform state changing requests on the application. If the victim ...
CVE-2023-50707HIGH7.5 Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service c...
CVE-2023-50706MEDIUM4.3 A user without administrator permissions with access to the UC500 windows system could perform a memory dum...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now