2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-46218MEDIUM6.5This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than w...
CVE-2023-6566MEDIUM6.5Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-46354HIGH7.5In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can d...
CVE-2023-46353CRITICAL9.8In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL inj...
CVE-2023-49096HIGH8.8Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument inj...
CVE-2023-48123HIGH8.8An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitra...
CVE-2023-46751HIGH7.5An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows r...
CVE-2023-6393MEDIUM5.3A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the ...
CVE-2023-45285HIGH7.5Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the...
CVE-2023-39326MEDIUM5.3A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read man...
CVE-2023-39539HIGH7.8 AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dange...
CVE-2023-39538HIGH7.8 AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dange...
CVE-2023-36655CRITICAL9.8The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a r...
CVE-2023-48859HIGH8.8TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows atta...
CVE-2023-6288HIGH7.8Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLI...
CVE-2023-32268HIGH7.2 Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credent...
CVE-2023-6514HIGH8.8 The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successf...
CVE-2023-6459MEDIUM5.3Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the ch...
CVE-2023-6458CRITICAL9.8Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perf...
CVE-2023-6273MEDIUM5.3Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerabi...
CVE-2023-49248MEDIUM5.5Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause u...
CVE-2023-49247HIGH7.5Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect...
CVE-2023-49246HIGH7.5Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affec...
CVE-2023-49245HIGH7.5Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect s...
CVE-2023-49244HIGH7.5Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect s...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now