2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-2063HIGH7.3Unrestricted Upload of File with Dangerous Type vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC ...
CVE-2023-2061HIGH7.5Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/...
CVE-2023-2060HIGH7.5Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/...
CVE-2023-2201HIGH8.8The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and i...
CVE-2023-29724HIGH7.8The BT21 x BTS Wallpaper app 12 for Android allows unauthorized apps to actively request permission to modify data in th...
CVE-2023-27745HIGH8.8An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform A...
CVE-2023-27744HIGH7.8An issue was discovered in South River Technologies TitanFTP NextGen server that allows for a vertical privilege escalat...
CVE-2023-29723HIGH7.5The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized applications to actively request permissi...
CVE-2023-27640HIGH7.5An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req...
CVE-2023-27639HIGH7.5An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP req...
CVE-2023-34092HIGH7.5Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`s...
CVE-2023-33960HIGH7.5OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated...
CVE-2023-32714HIGH8.1In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web ...
CVE-2023-32708HIGH8.8In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a ...
CVE-2023-32707HIGH8.8In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, ...
CVE-2023-32690HIGH7.5libspdm is a sample implementation that follows the DMTF SPDM specifications. Prior to versions 2.3.3 and 3.0, following...
CVE-2023-32310HIGH8.1DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and del...
CVE-2023-28066HIGH7.8 Dell OS Recovery Tool, versions 2.2.4013 and 2.3.7012.0, contain an Improper Access Control Vulnerability. A local auth...
CVE-2023-33965HIGH8.8Brook is a cross-platform programmable network tool. The `tproxy` server is vulnerable to a drive-by command injection. ...
CVE-2023-33552HIGH7.8Heap Buffer Overflow in the erofs_read_one_data function at data.c in erofs-utils v1.6 allows remote attackers to execut...
CVE-2023-33551HIGH7.8Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to...
CVE-2023-22648HIGH8.8A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected ...
CVE-2023-22647HIGH8An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permiss...
CVE-2023-3029HIGH8.8A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. Th...
CVE-2023-34312HIGH7.8In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate poi...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now