2023 CVE Vulnerabilities

31,249 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-0464HIGH7.5A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 ...
CVE-2023-1578HIGH8.8SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.
CVE-2023-1281HIGH7.8Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imp...
CVE-2023-1559HIGH7.2A vulnerability classified as problematic was found in SourceCodester Storage Unit Rental Management System 1.0. This vu...
CVE-2023-28685HIGH7.1Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attack...
CVE-2023-25924HIGH8.8IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform...
CVE-2023-25594HIGH8.8 A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only pri...
CVE-2023-25590HIGH7.8A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their us...
CVE-2023-25069HIGH8.8TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 tha...
CVE-2023-1436HIGH7.5An infinite recursion is triggered in Jettison when constructing a JSONArray from a Collection that contains a self-refe...
CVE-2023-1370HIGH7.5[Json-smart](https://netplex.github.io/json-smart/) is a performance focused, JSON processor lib. When reaching a ‘[‘ o...
CVE-2023-1168HIGH8.8An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful e...
CVE-2023-27857HIGH7.5 In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than i...
CVE-2023-27856HIGH7.5 In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManage...
CVE-2023-24709HIGH7.5An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l...
CVE-2023-1534HIGH8.8Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the r...
CVE-2023-1533HIGH8.8Use after free in WebProtect in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit h...
CVE-2023-1532HIGH8.8Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploi...
CVE-2023-1531HIGH8.8Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap c...
CVE-2023-1530HIGH8.8Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap cor...
CVE-2023-1528HIGH8.8Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the r...
CVE-2023-0391HIGH8.1MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, s...
CVE-2023-27087HIGH7.5Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive infor...
CVE-2023-1306HIGH8.8An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jin...
CVE-2023-1305HIGH8.1An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided tho...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now