2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29255 | HIGH | 7.5 | 1.0% | Apr 27, 2023 | IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv... |
| CVE-2023-2338 | HIGH | 8.8 | 0.9% | Apr 27, 2023 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.21. |
| CVE-2023-2331 | HIGH | 7.8 | 0.2% | Apr 27, 2023 | Unquoted service Path or Element vulnerability in 42Gears Surelock Windows SureLock Service (NixService.Exe) on Windows ... |
| CVE-2023-28770 | HIGH | 7.5 | 57.8% | Apr 27, 2023 | The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmwa... |
| CVE-2023-31287 | HIGH | 7.8 | 0.4% | Apr 27, 2023 | An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link... |
| CVE-2023-24836 | HIGH | 8.8 | 1.2% | Apr 27, 2023 | SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker wit... |
| CVE-2023-26246 | HIGH | 7.8 | 0.3% | Apr 27, 2023 | An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUp... |
| CVE-2023-26245 | HIGH | 7.8 | 0.3% | Apr 27, 2023 | An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUp... |
| CVE-2023-26244 | HIGH | 7.8 | 0.3% | Apr 27, 2023 | An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDM... |
| CVE-2023-26243 | HIGH | 7.8 | 0.3% | Apr 27, 2023 | An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decry... |
| CVE-2023-2297 | HIGH | 8.1 | 1.0% | Apr 27, 2023 | The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password... |
| CVE-2023-27107 | HIGH | 8.8 | 0.8% | Apr 26, 2023 | Incorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server b... |
| CVE-2023-30846 | HIGH | 7.5 | 2.2% | Apr 26, 2023 | typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-r... |
| CVE-2023-2291 | HIGH | 7.8 | 0.8% | Apr 26, 2023 | Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine ... |
| CVE-2023-29835 | HIGH | 7.8 | 0.4% | Apr 26, 2023 | Insecure Permission vulnerability found in Wondershare Dr.Fone v.12.9.6 allows a remote attacker to escalate privileges ... |
| CVE-2023-29596 | HIGH | 7.8 | 0.3% | Apr 26, 2023 | Buffer Overflow vulnerability found in ByronKnoll Cmix v.19 allows an attacker to execute arbitrary code and cause a den... |
| CVE-2023-28009 | HIGH | 8.1 | 0.8% | Apr 26, 2023 | HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remot... |
| CVE-2023-28008 | HIGH | 8.1 | 0.8% | Apr 26, 2023 | HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processi... |
| CVE-2023-27559 | HIGH | 7.5 | 0.9% | Apr 26, 2023 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv... |
| CVE-2023-26567 | HIGH | 8.1 | 0.6% | Apr 26, 2023 | Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPAS... |
| CVE-2023-30546 | HIGH | 7.5 | 0.6% | Apr 26, 2023 | Contiki-NG is an operating system for Internet of Things devices. An off-by-one error can be triggered in the Antelope d... |
| CVE-2023-30269 | HIGH | 8.1 | 0.7% | Apr 26, 2023 | CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php. |
| CVE-2023-30266 | HIGH | 8.8 | 0.8% | Apr 26, 2023 | CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. |
| CVE-2023-30112 | HIGH | 7.5 | 0.6% | Apr 26, 2023 | Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection. |
| CVE-2023-1387 | HIGH | 7.5 | 1.5% | Apr 26, 2023 | Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now