2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-48084CRITICAL9.8Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.
CVE-2023-25651HIGH8 There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SM...
CVE-2023-25650MEDIUM6.5 There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or...
CVE-2023-25648HIGH7.8 There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attack...
CVE-2023-44709CRITICAL9.8PlutoSVG commit 336c02997277a1888e6ccbbbe674551a0582e5c4 and before was discovered to contain an integer overflow via th...
CVE-2023-6407HIGH7.1 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that coul...
CVE-2023-5630MEDIUM4.9 A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to instal...
CVE-2023-5629MEDIUM6.1 A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of infor...
CVE-2023-49938HIGH8.2An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modifie...
CVE-2023-49937CRITICAL9.8An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a ...
CVE-2023-49936HIGH7.5An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. A NULL pointer dereference leads to denial of se...
CVE-2023-49935HIGH8.8An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Mess...
CVE-2023-49934CRITICAL9.8An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed versio...
CVE-2023-49933HIGH7.5An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. There is Improper Enforcement of Message Integri...
CVE-2023-45184HIGH7.5IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryp...
CVE-2023-41720HIGH7.8A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Iva...
CVE-2023-41719HIGH7.2A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administ...
CVE-2023-43042HIGH7.5IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords f...
CVE-2023-31546CRITICAL9.6Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature...
CVE-2023-41618MEDIUM6.1Emlog Pro v2.1.14 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /adm...
CVE-2023-40921CRITICAL9.8SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to ...
CVE-2023-21751MEDIUM6.5Azure DevOps Server Spoofing Vulnerability
CVE-2023-49646MEDIUM6.5Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial o...
CVE-2023-45174HIGH7.8IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to ...
CVE-2023-45170HIGH7.8IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now