2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-29815HIGH8.8mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2023-1477HIGH8.8Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue af...
CVE-2023-2373HIGH7.2A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This vulnerability affects unknown code of...
CVE-2023-2360HIGH7.5Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infras...
CVE-2023-28882HIGH7.5Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) be...
CVE-2023-28528HIGH7.8IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout c...
CVE-2023-31436HIGH7.8qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can...
CVE-2023-27557HIGH7.5IBM Counter Fraud Management for Safer Payments 6.1.0.00 through 6.1.1.02, 6.2.0.00 through 6.2.2.02, 6.3.0.00 through 6...
CVE-2023-27556HIGH7.5IBM Counter Fraud Management for Safer Payments 6.1.0.00, 6.2.0.00, 6.3.0.00 through 6.3.1.03, 6.4.0.00 through 6.4.2.02...
CVE-2023-2356HIGH7.5Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.
CVE-2023-29169HIGH8.8mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope...
CVE-2023-29150HIGH8.8mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope...
CVE-2023-28716HIGH8.8mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope...
CVE-2023-28400HIGH8.8mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope...
CVE-2023-28384HIGH8.8mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary ope...
CVE-2023-30380HIGH7.5An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal...
CVE-2023-25437HIGH8.8An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges an...
CVE-2023-2355HIGH7.8Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deplo...
CVE-2023-21712HIGH8.1Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-2335HIGH7.5 Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Regi...
CVE-2023-30850HIGH8.8Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerabili...
CVE-2023-30624HIGH8.8Wasmtime is a standalone runtime for WebAssembly. Prior to versions 6.0.2, 7.0.1, and 8.0.1, Wasmtime's implementation o...
CVE-2023-30849HIGH8.8Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerabili...
CVE-2023-30848HIGH8.8Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API h...
CVE-2023-30847HIGH8.2H2O is an HTTP server. In versions 2.3.0-beta2 and prior, when the reverse proxy handler tries to processes a certain ty...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now