2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-42004HIGH8.8IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote attacker could execute ...
CVE-2023-6151HIGH7.5Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided b...
CVE-2023-6150HIGH7.5Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided b...
CVE-2023-4667MEDIUM4.8 The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fie...
CVE-2023-34055MEDIUM6.5In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially cra...
CVE-2023-34054HIGH7.5 In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a u...
CVE-2023-34053HIGH7.5In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that m...
CVE-2023-4226HIGH8.8Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers wit...
CVE-2023-4225HIGH8.8Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers...
CVE-2023-4224HIGH8.8Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers ...
CVE-2023-4223HIGH8.8Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers...
CVE-2023-4222HIGH8.8Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to u...
CVE-2023-4221HIGH8.8Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to up...
CVE-2023-4220MEDIUM6.1Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in C...
CVE-2023-48023CRITICAL9.1Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant becau...
CVE-2023-48022CRITICAL9.8Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve...
CVE-2023-3545CRITICAL9.8Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installation...
CVE-2023-3533CRITICAL9.8Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20...
CVE-2023-3368CRITICAL9.8Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated at...
CVE-2023-24023MEDIUM6.8Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 t...
CVE-2023-6226MEDIUM4.3The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Insecure Direct Object Reference in...
CVE-2023-6225MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2023-49075HIGH7.2The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introdu...
CVE-2023-48713MEDIUM5.3Knative Serving builds on Kubernetes to support deploying and serving of applications and functions as serverless contai...
CVE-2023-32065MEDIUM5.8OroCommerce is an open-source Business to Business Commerce application built with flexibility in mind. Detailed Order t...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now