2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-29063LOW2.4The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat ...
CVE-2023-29062LOW3.8The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials u...
CVE-2023-29061MEDIUM5.2There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to the workstation can pote...
CVE-2023-45539HIGH8.2HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive info...
CVE-2023-30590HIGH7.5The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, th...
CVE-2023-30588MEDIUM5.3When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect ter...
CVE-2023-29060MEDIUM5.7The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited...
CVE-2023-49078MEDIUM6.1raptor-web is a CMS for game server communities that can be used to host information and keep track of players. In versi...
CVE-2023-48121MEDIUM5.3An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 2023040...
CVE-2023-42504MEDIUM6.5An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports,...
CVE-2023-40056HIGH8.8 SQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be expl...
CVE-2023-48848HIGH7.5An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server ...
CVE-2023-45286MEDIUM5.9A race condition in go-resty can result in HTTP request body disclosure across requests. This condition can be triggered...
CVE-2023-42505MEDIUM4.3An authenticated user with read permissions on database connections metadata could potentially access sensitive informat...
CVE-2023-42502MEDIUM5.4An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing t...
CVE-2023-41264CRITICAL9.8Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on dep...
CVE-2023-49062HIGH7.5Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulatio...
CVE-2023-46589HIGH7.5Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 throug...
CVE-2023-49314HIGH7.8Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection ag...
CVE-2023-49313CRITICAL9.8A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unaut...
CVE-2023-6239HIGH8.8Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specif...
CVE-2023-48042MEDIUM6.1Cross Site Scripting (XSS) in Search filters in Prestashop Amazzing filter version up to version 3.2.5, allows remote at...
CVE-2023-6359MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability has been found in Alumne LMS affecting version 4.0.0.1.08. An attacker could ...
CVE-2023-6201HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Comp...
CVE-2023-5981MEDIUM5.9A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from resp...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now