2023 CVE Vulnerabilities

31,250 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-26284HIGH8.8IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the ...
CVE-2023-24229HIGH7.8DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to injec...
CVE-2023-1415HIGH8.8A vulnerability was found in Simple Art Gallery 1.0. It has been declared as critical. This vulnerability affects the fu...
CVE-2023-27781HIGH7.8jpegoptim v1.5.2 was discovered to contain a heap overflow in the optimize function at jpegoptim.c.
CVE-2023-27103HIGH8.8Libde265 v1.0.11 was discovered to contain a heap buffer overflow via the function derive_collocated_motion_vectors at m...
CVE-2023-0100HIGH8.8In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host ...
CVE-2023-24732HIGH8.8Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gende...
CVE-2023-24731HIGH8.8Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query...
CVE-2023-24730HIGH8.8Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the compa...
CVE-2023-24729HIGH8.8Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the addre...
CVE-2023-24728HIGH8.8Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the conta...
CVE-2023-25968HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Madalin Ungureanu, Antohe Cristian Client Portal – Privat...
CVE-2023-25709HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.11 versions.
CVE-2023-25708HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Rextheme WP VR – 360 Panorama and Virtual Tour Builder For WordPress ...
CVE-2023-1407HIGH7.2A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affe...
CVE-2023-27235HIGH7.2An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attacker...
CVE-2023-27590HIGH7.8Rizin is a UNIX-like reverse engineering framework and command-line toolset. In version 0.5.1 and prior, converting a GD...
CVE-2023-26262HIGH7.2An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload v...
CVE-2023-28339HIGH8.8OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the or...
CVE-2023-28144HIGH7KDAB Hotspot 1.3.x and 1.4.x through 1.4.1, in a non-default configuration, allows privilege escalation because of race ...
CVE-2023-27588HIGH7.5Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been disco...
CVE-2023-27585HIGH7.5PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versio...
CVE-2023-25206HIGH8.8PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.
CVE-2023-24930HIGH7.8Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
CVE-2023-24913HIGH8.8Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now