2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-29255HIGH7.5IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv...
CVE-2023-2338HIGH8.8SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.21.
CVE-2023-2331HIGH7.8Unquoted service Path or Element vulnerability in 42Gears Surelock Windows SureLock Service (NixService.Exe) on Windows ...
CVE-2023-28770HIGH7.5The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmwa...
CVE-2023-31287HIGH7.8An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link...
CVE-2023-24836HIGH8.8SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker wit...
CVE-2023-26246HIGH7.8An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUp...
CVE-2023-26245HIGH7.8An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUp...
CVE-2023-26244HIGH7.8An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDM...
CVE-2023-26243HIGH7.8An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decry...
CVE-2023-2297HIGH8.1The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password...
CVE-2023-27107HIGH8.8Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server b...
CVE-2023-30846HIGH7.5typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-r...
CVE-2023-2291HIGH7.8Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine ...
CVE-2023-29835HIGH7.8Insecure Permission vulnerability found in Wondershare Dr.Fone v.12.9.6 allows a remote attacker to escalate privileges ...
CVE-2023-29596HIGH7.8Buffer Overflow vulnerability found in ByronKnoll Cmix v.19 allows an attacker to execute arbitrary code and cause a den...
CVE-2023-28009HIGH8.1HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remot...
CVE-2023-28008HIGH8.1HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processi...
CVE-2023-27559HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv...
CVE-2023-26567HIGH8.1Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPAS...
CVE-2023-30546HIGH7.5Contiki-NG is an operating system for Internet of Things devices. An off-by-one error can be triggered in the Antelope d...
CVE-2023-30269HIGH8.1CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php.
CVE-2023-30266HIGH8.8CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type.
CVE-2023-30112HIGH7.5Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection.
CVE-2023-1387HIGH7.5Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now