2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48378HIGH7.5Softnext Mail SQR Expert has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated r...
CVE-2023-48376CRITICAL9.8SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file...
CVE-2023-48375HIGH8.8SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users ar...
CVE-2023-48374MEDIUM6.5SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific a...
CVE-2023-48373HIGH7.5ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauth...
CVE-2023-48372CRITICAL9.8ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attack...
CVE-2023-48371CRITICAL9.8ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated r...
CVE-2023-50715MEDIUM4.3Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active ...
CVE-2023-6832MEDIUM4.3Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-6831HIGH8.1Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
CVE-2023-48050CRITICAL9.8SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka ...
CVE-2023-42183MEDIUM5.3lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization, which may allow bypass of i...
CVE-2023-40954CRITICAL9.8A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12...
CVE-2023-36878MEDIUM4.3Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2023-48049CRITICAL9.8A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through...
CVE-2023-4489CRITICAL9.8The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP G...
CVE-2023-6707HIGH8.8Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap cor...
CVE-2023-6706HIGH8.8Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engag...
CVE-2023-6705HIGH8.8Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap ...
CVE-2023-6704HIGH8.8Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap...
CVE-2023-6703HIGH8.8Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap c...
CVE-2023-6702HIGH8.8Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corr...
CVE-2023-6134MEDIUM5.4A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to t...
CVE-2023-49347HIGH7.8Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or ma...
CVE-2023-49346HIGH7.8Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now