2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-28051HIGH7.8 Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attack...
CVE-2023-26820HIGH7.5siteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js.
CVE-2023-26817HIGH8.8codefever before 2023.2.7-commit-b1c2e7f was discovered to contain a remote code execution (RCE) vulnerability via the c...
CVE-2023-20655HIGH7.8In mmsdk, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local code exe...
CVE-2023-29008HIGH8.8The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` ...
CVE-2023-24537HIGH7.5Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can c...
CVE-2023-24536HIGH7.5Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large num...
CVE-2023-24534HIGH7.5HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading t...
CVE-2023-23801HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions.
CVE-2023-0652HIGH7.8Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WA...
CVE-2023-1802HIGH7.5In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the H...
CVE-2023-28046HIGH7.1 Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder deletion vulnerability during unin...
CVE-2023-25542HIGH7.8 Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An u...
CVE-2023-29421HIGH8.8An issue was discovered in libbzip3.a in bzip3 before 1.2.3. There is an out-of-bounds write in bz3_decode_block.
CVE-2023-1733HIGH7.5A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 1...
CVE-2023-28342HIGH7.5Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App ...
CVE-2023-20122HIGH7.8Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Se...
CVE-2023-20117HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN ...
CVE-2023-20103HIGH7.2A vulnerability in Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary cod...
CVE-2023-20102HIGH8.8A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, re...
CVE-2023-1838HIGH7.1A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Li...
CVE-2023-1522HIGH8.8SQL Injection in the Hardware Inventory report of Security Center 5.11.2.
CVE-2023-0670HIGH7.2Ulearn version a5a7ca20de859051ea0470542844980a66dfc05d allows an attacker with administrator permissions to obtain remo...
CVE-2023-29006HIGH8.8The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to vers...
CVE-2023-28838HIGH8.1GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 9.5.13 and 10.0....

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now