2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-4931HIGH7.8Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execu...
CVE-2023-4590CRITICAL9.8Buffer overflow vulnerability in Frhed hex editor, affecting version 1.6.0. This vulnerability could allow an attacker t...
CVE-2023-5871MEDIUM5.3A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such a...
CVE-2023-5607HIGH7.2 An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extensio...
CVE-2023-43701MEDIUM5.4Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious acto...
CVE-2023-42501MEDIUM4.3Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and ...
CVE-2023-40610HIGH8.8Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the d...
CVE-2023-6254HIGH7.5A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send b...
CVE-2023-6202MEDIUM4.3Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker w...
CVE-2023-49068HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects A...
CVE-2023-48369MEDIUM5.3Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to differe...
CVE-2023-48268HIGH7.5Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards...
CVE-2023-47168MEDIUM6.1Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user cli...
CVE-2023-45223MEDIUM4.3Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a me...
CVE-2023-43754MEDIUM4.3Mattermost fails to check whether the  “Allow users to view archived channels”  setting is enabled during permalink prev...
CVE-2023-40703HIGH7.5Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a...
CVE-2023-35075MEDIUM5.4Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowi...
CVE-2023-47865MEDIUM4.3Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. ...
CVE-2023-25632MEDIUM5.5The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open ...
CVE-2023-6313MEDIUM6.1A vulnerability was found in SourceCodester URL Shortener 1.0. It has been declared as problematic. Affected by this vul...
CVE-2023-6312HIGH7.2A vulnerability was found in SourceCodester Loan Management System 1.0. It has been classified as critical. Affected is ...
CVE-2023-6311HIGH7.2A vulnerability was found in SourceCodester Loan Management System 1.0 and classified as critical. This issue affects th...
CVE-2023-6310HIGH7.2A vulnerability has been found in SourceCodester Loan Management System 1.0 and classified as critical. This vulnerabili...
CVE-2023-6309CRITICAL9.8A vulnerability, which was classified as critical, was found in moses-smt mosesdecoder up to 4.0. This affects an unknow...
CVE-2023-6308HIGH8.8A vulnerability, which was classified as critical, has been found in Xiamen Four-Faith Video Surveillance Management Sys...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now