2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-2928HIGH8.8A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is ...
CVE-2023-26129HIGH7.8All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check'...
CVE-2023-26128HIGH7.8All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or ...
CVE-2023-26127HIGH7.8All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.e...
CVE-2023-33192HIGH7.5ntpd-rs is an NTP implementation written in Rust. ntpd-rs does not validate the length of NTS cookies in received NTP pa...
CVE-2023-32688HIGH7.5parse-server-push-adapter is the official Push Notification adapter for Parse Server. The Parse Server Push Adapter can ...
CVE-2023-32676HIGH7.2Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was fo...
CVE-2023-32317HIGH7.2Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was fo...
CVE-2023-32315HIGH7.5Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based...
CVE-2023-32307HIGH7.5Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-85...
CVE-2023-31128HIGH8.8NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `...
CVE-2023-21515HIGH8.8InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 al...
CVE-2023-21514HIGH8.8Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execu...
CVE-2023-2879HIGH7.5GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or cra...
CVE-2023-2825HIGH7.5An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a ...
CVE-2023-28319HIGH7.5A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's publ...
CVE-2023-33247HIGH7.5Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthentic...
CVE-2023-22970HIGH7.8Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
CVE-2023-33779HIGH8.8A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another use...
CVE-2023-31227HIGH7.5The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may...
CVE-2023-31226HIGH7.5The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vul...
CVE-2023-20883HIGH7.5In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, th...
CVE-2023-0116HIGH7.5The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerabi...
CVE-2023-33440HIGH7.2Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_u...
CVE-2023-33439HIGH7.2Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=.

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now