2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-3145HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Online Discussion Forum Site 1.0. Af...
CVE-2023-20889HIGH7.5Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to ...
CVE-2023-20888HIGH8.8Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network acc...
CVE-2023-33498HIGH8.8alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.
CVE-2023-30576HIGH8.1Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, thi...
CVE-2023-30575HIGH7.5Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole...
CVE-2023-1388HIGH8.1 A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the mac...
CVE-2023-0976HIGH7.8 A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file...
CVE-2023-33538HIGH8.8TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili...
CVE-2023-33537HIGH8.1TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the compo...
CVE-2023-33536HIGH8.1TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the compo...
CVE-2023-3124HIGH8.8The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check...
CVE-2023-33601HIGH8.8An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary co...
CVE-2023-33782HIGH8.8D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.
CVE-2023-33781HIGH8.8An issue in D-Link DIR-842V2 v1.0.3 allows attackers to execute arbitrary commands via importing a crafted file.
CVE-2023-33569HIGH7.2Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=upda...
CVE-2023-2603HIGH7.8A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overf...
CVE-2023-33959HIGH8.8notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry...
CVE-2023-33653HIGH8.8Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerabil...
CVE-2023-33652HIGH8.8Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerabil...
CVE-2023-33651HIGH7.5An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Comme...
CVE-2023-34104HIGH7.5fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names...
CVE-2023-33747HIGH7.8CloudPanel v2.2.2 allows attackers to execute a path traversal.
CVE-2023-32203HIGH7.8Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This coul...
CVE-2023-31606HIGH7.5A Regular Expression Denial of Service (ReDoS) issue was discovered in the sanitize_html function of redcloth gem v4.0.0...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now