2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-2690HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Personnel Property Equipment System ...
CVE-2023-2689HIGH8.8A vulnerability classified as critical was found in SourceCodester Billing Management System 1.0. This vulnerability aff...
CVE-2023-25009HIGH7.8A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds write vulnerability...
CVE-2023-25008HIGH7.8A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability ...
CVE-2023-25007HIGH7.8A malicious actor may convince a user to open a malicious USD file that may trigger an uninitialized pointer which could...
CVE-2023-25006HIGH7.8A malicious actor may convince a user to open a malicious USD file that may trigger a use-after-free vulnerability which...
CVE-2023-25005HIGH7.8A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 w...
CVE-2023-20878HIGH7.2VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can ex...
CVE-2023-20877HIGH8.8VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly priv...
CVE-2023-32305HIGH8.8aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing e...
CVE-2023-2458HIGH8.8Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who con...
CVE-2023-2457HIGH8.8Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attac...
CVE-2023-25927HIGH7.5IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webse...
CVE-2023-25428HIGH7.8A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leadin...
CVE-2023-31197HIGH7.8Uncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenti...
CVE-2023-29242HIGH7.8Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to po...
CVE-2023-32073HIGH8.8WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `p...
CVE-2023-31922HIGH7.5QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.
CVE-2023-1934HIGH7.5The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL...
CVE-2023-23444HIGH8.2Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 104...
CVE-2023-30130HIGH8.8An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Sectio...
CVE-2023-2512HIGH8.1Prior to version v1.20230419.0, the FormData API implementation was subject to an integer overflow. If a FormData instan...
CVE-2023-29657HIGH8.8eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing...
CVE-2023-2677HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Covid-19 Contact Tracing System 1.0. This...
CVE-2023-2515HIGH8.8Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from eleva...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now