2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-48084 | CRITICAL | 9.8 | 33.7% | Dec 14, 2023 | Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool. |
| CVE-2023-25651 | HIGH | 8 | 0.3% | Dec 14, 2023 | There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SM... |
| CVE-2023-25650 | MEDIUM | 6.5 | 0.6% | Dec 14, 2023 | There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or... |
| CVE-2023-25648 | HIGH | 7.8 | 0.2% | Dec 14, 2023 | There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attack... |
| CVE-2023-44709 | CRITICAL | 9.8 | 0.8% | Dec 14, 2023 | PlutoSVG commit 336c02997277a1888e6ccbbbe674551a0582e5c4 and before was discovered to contain an integer overflow via th... |
| CVE-2023-6407 | HIGH | 7.1 | 0.2% | Dec 14, 2023 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that coul... |
| CVE-2023-5630 | MEDIUM | 4.9 | 0.3% | Dec 14, 2023 | A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to instal... |
| CVE-2023-5629 | MEDIUM | 6.1 | 0.4% | Dec 14, 2023 | A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of infor... |
| CVE-2023-49938 | HIGH | 8.2 | 0.7% | Dec 14, 2023 | An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modifie... |
| CVE-2023-49937 | CRITICAL | 9.8 | 1.4% | Dec 14, 2023 | An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a ... |
| CVE-2023-49936 | HIGH | 7.5 | 1.1% | Dec 14, 2023 | An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. A NULL pointer dereference leads to denial of se... |
| CVE-2023-49935 | HIGH | 8.8 | 1.0% | Dec 14, 2023 | An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Mess... |
| CVE-2023-49934 | CRITICAL | 9.8 | 0.8% | Dec 14, 2023 | An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed versio... |
| CVE-2023-49933 | HIGH | 7.5 | 0.4% | Dec 14, 2023 | An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. There is Improper Enforcement of Message Integri... |
| CVE-2023-45184 | HIGH | 7.5 | 1.6% | Dec 14, 2023 | IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryp... |
| CVE-2023-41720 | HIGH | 7.8 | 0.7% | Dec 14, 2023 | A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Iva... |
| CVE-2023-41719 | HIGH | 7.2 | 3.4% | Dec 14, 2023 | A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administ... |
| CVE-2023-43042 | HIGH | 7.5 | 0.7% | Dec 14, 2023 | IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords f... |
| CVE-2023-31546 | CRITICAL | 9.6 | 49.4% | Dec 14, 2023 | Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature... |
| CVE-2023-41618 | MEDIUM | 6.1 | 0.5% | Dec 14, 2023 | Emlog Pro v2.1.14 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /adm... |
| CVE-2023-40921 | CRITICAL | 9.8 | 0.5% | Dec 14, 2023 | SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to ... |
| CVE-2023-21751 | MEDIUM | 6.5 | 1.0% | Dec 14, 2023 | Azure DevOps Server Spoofing Vulnerability |
| CVE-2023-49646 | MEDIUM | 6.5 | 0.4% | Dec 13, 2023 | Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial o... |
| CVE-2023-45174 | HIGH | 7.8 | 0.2% | Dec 13, 2023 | IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a privileged local user to exploit a vulnerability in the qdaemon command to ... |
| CVE-2023-45170 | HIGH | 7.8 | 0.2% | Dec 13, 2023 | IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the piobe command t... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now